{"id":"CVE-2026-107376","summary":"webonyx graphql-php: Unbounded recursion in parser causes stack overflow on crafted nested input","details":"webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\\Language\\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote attacker can submit deeply nested selection sets, object or list values, or list types that exhaust the PHP process stack during pre-validation parsing, before query validation and complexity controls run. The resulting SIGSEGV can terminate PHP-FPM workers or long-running Swoole, RoadRunner, ReactPHP, or CLI processes and cannot be caught by application-level exception handling. This issue is fixed in version 15.32.3.","aliases":["GHSA-r7cg-qjjm-xhqq"],"modified":"2026-10-09T10:30:27.746973091Z","published":"2026-10-08T17:49:57.113Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107376.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-674"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107376.json"},{"type":"FIX","url":"https://github.com/webonyx/graphql-php/commit/6c1d6009a0f7557f66753bcfd07badd15acf77f4"},{"type":"FIX","url":"https://github.com/webonyx/graphql-php/commit/7b7f2080ca5f7d5340a696fc5701b19a9222d2c2"},{"type":"WEB","url":"https://github.com/webonyx/graphql-php/releases/tag/v15.32.3"},{"type":"ADVISORY","url":"https://github.com/webonyx/graphql-php/security/advisories/GHSA-r7cg-qjjm-xhqq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107376"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webonyx/graphql-php","events":[{"introduced":"0"},{"fixed":"993bf0bea17f870412ad8a90f60c41cb8d5f1145"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"15.32.3"}]}}],"versions":["v15.32.2","v15.32.1","v15.32.0","v15.31.5","v15.31.4","v15.31.3","v15.31.2","v15.31.1","v15.31.0","v15.30.2","v15.30.1","v15.30.0","v15.29.4","v15.29.3","v15.29.2","v15.29.1","v15.29.0","v15.28.0","v15.27.2","v15.27.1","v15.27.0","v15.26.0","v15.25.2","v15.25.1","v15.25.0","v15.24.0","v15.23.1","v15.23.0","v15.22.4","v15.22.3","v15.22.2","v15.22.1","v15.22.0","v15.21.3","v15.21.2","v15.21.1","v15.21.0","v15.20.1","v15.20.0","v15.19.1","v15.19.0","v15.18.1","v15.18.0","v15.17.0","v15.16.1","v15.16.0","v15.15.0","v15.14.3","v15.14.2","v15.14.1","v15.14.0","v15.13.0","v15.12.5","v15.12.4","v15.12.3","v15.12.2","v15.12.1","v15.12.0","v15.11.2","v15.11.1","v15.11.0","v15.10.0","v15.9.1","v15.9.0","v15.8.1","v15.8.0","v15.7.0","v15.6.3","v15.6.2","v15.6.1","v15.6.0","v15.5.3","v15.5.2","v15.5.1","v15.5.0","v15.4.0","v15.3.2","v15.3.1","v15.3.0","v15.2.5","v15.2.4","v15.2.3","v15.2.2","v15.2.1","v15.2.0","v15.1.0","v15.0.3","v15.0.2","v15.0.1","v15.0.0","v15.0.0-beta.1","v15.0.0-alpha.2","v15.0.0-alpha.1","v14.5.1","v14.5.0","v14.4.1","v14.4.0","v14.3.0","v14.2.0","v14.1.1","v14.1.0","v14.0.2","v14.0.1","v14.0.0","v0.13.0","v0.12.1","v0.12.0","v0.11.5","v0.11.4","v0.11.3","v0.11.2","v0.11.1","v0.11.0","v0.10.2","v0.10.1","v0.10.0","v0.10.0-rc1","v0.9.10","v0.9.9","v0.9.8","v0.9.7","v0.9.6","v0.9.5","v0.9.4","v0.9.3","v0.9.2","v0.9.1","v0.9.0","v0.8.0","v0.7.2","v0.7.1","v0.7.0","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.6.0","v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107376.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}