Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-104852 – Prototype Pollution / Denial of Service – GraphQL Tools (@graphql-tools/utils) ≤ 1

Be the first to know when new zero-days emerge:

Summary

CVE-2026-104852 is a prototype pollution vulnerability (CWE-1321) in the mergeDeep utility function shipped in @graphql-tools/utils, part of the widely used GraphQL Tools (ardatan/graphql-tools) library. An unauthenticated remote attacker can craft a GraphQL query that causes mergeDeep to merge attacker-controlled keys such as __proto__, constructor, or prototype into Object.prototype/Function.prototype, corrupting shared JavaScript runtime state. The issue carries a CVSS v4.0 base score of 8.2 (High) and results in a denial-of-service condition affecting the whole process, not just the originating request.

Technical details

  • Root cause: mergeDeep recursively merged source object keys into a target object without filtering dangerous keys (__proto__, constructor, prototype) and used the in operator (which traverses the prototype chain) rather than hasOwnProperty to decide whether a key already existed on the target.
  • Trigger conditions: In a federated/stitched GraphQL setup (supergraph), a client can alias response fields to names like __proto__ so that results returned from two different subgraphs collide during ordinary result merging. This causes the polluted key to be written onto a shared object prototype (e.g., Function.prototype.call).
  • Attack vector: Network-based, no authentication, and no special user interaction required (CVSS v4.0 vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). The attack requires some attacker-controlled conditions (AT:P) — i.e., a gateway that merges/stitches results from multiple subgraphs using the vulnerable merge logic.
  • Impact: Once a core prototype method (such as Function.prototype.call) is overwritten, subsequent, unrelated requests handled by the same Node.js process can fail or behave unpredictably until the process is restarted — resulting in a process-wide availability (denial-of-service) impact. The advisory records no confidentiality or integrity impact.

Affected software

  • @graphql-tools/utils versions up to and including 12.0.0
  • Any ardatan/graphql-tools packages and downstream consumers (e.g., GraphQL gateway/stitching tools) that depend on the vulnerable mergeDeep implementation in @graphql-tools/utils prior to the fix
  • Fixed in @graphql-tools/utils 12.0.1 and later (with additional hardening released in subsequent 12.0.x versions)

Severity

  • CVSS v4.0 Base Score: 8.2 (High)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)

Mitigation and recommended actions

  • Immediate: Upgrade @graphql-tools/utils (and any dependent graphql-tools packages) to version 12.0.1 or later. The fix skips source keys named __proto__, constructor, or prototype at every recursion level in mergeDeep, and replaces the in operator check with hasOwnProperty so inherited properties can no longer be used as merge targets. Note that follow-up hardening releases (12.0.2 and 12.0.3) further closed related gaps in incremental-result path merging — upgrading to the latest 12.0.x release is recommended rather than stopping at 12.0.1.
  • If immediate patching is not possible:
    • Restrict or disable field aliasing to reserved prototype-related names (__proto__, constructor, prototype) at the gateway/proxy layer if such filtering capability exists.
    • Monitor and alert on unexpected process restarts or request failures in GraphQL gateway/stitching services, which may indicate active exploitation.
    • Limit exposure of federated/stitched GraphQL endpoints that merge results from multiple subgraphs to trusted networks where feasible, as the vulnerability specifically affects result-merging logic used in supergraph configurations.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge