<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>appsec.fyi — GraphQL</title>
  <link>https://appsec.fyi/graphql.html</link>
  <description>Curated GraphQL resources from appsec.fyi</description>
  <language>en-us</language>
  <atom:link href="https://appsec.fyi/feeds/graphql.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Thu, 23 Apr 2026 23:07:09 +0000</lastBuildDate>
  <managingEditor>carl@chs.us (Carl Sampson)</managingEditor>
  <item>
    <title>CVE-2025-59845: CSRF Vulnerability in Apollo Studio Embeddable Explorer and Sandbox</title>
    <link>https://www.ameeba.com/blog/cve-2025-59845-csrf-vulnerability-in-apollo-studio-embeddable-explorer-embeddable-sandbox/</link>
    <guid isPermaLink="true">https://www.ameeba.com/blog/cve-2025-59845-csrf-vulnerability-in-apollo-studio-embeddable-explorer-embeddable-sandbox/</guid>
    <description>CVE-2025-59845: CSRF Vulnerability in Apollo Studio Embeddable Explorer and Sandbox</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:45 +0000</pubDate>
  </item>
  <item>
    <title>CVE-2025-31496: GraphQL Query Vulnerability in Apollo Compiler Leading to DoS</title>
    <link>https://www.ameeba.com/blog/cve-2025-31496-graphql-query-vulnerability-in-apollo-compiler-leading-to-possible-denial-of-service/</link>
    <guid isPermaLink="true">https://www.ameeba.com/blog/cve-2025-31496-graphql-query-vulnerability-in-apollo-compiler-leading-to-possible-denial-of-service/</guid>
    <description>CVE-2025-31496: GraphQL Query Vulnerability in Apollo Compiler Leading to DoS</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:45 +0000</pubDate>
  </item>
  <item>
    <title>The 16-Hour Window: Catching a GraphQL Authorization Flaw</title>
    <link>https://amannsharmaa.medium.com/the-16-hour-window-catching-a-graphql-authorization-flaw-575f6e5c1217</link>
    <guid isPermaLink="true">https://amannsharmaa.medium.com/the-16-hour-window-catching-a-graphql-authorization-flaw-575f6e5c1217</guid>
    <description>The 16-Hour Window: Catching a GraphQL Authorization Flaw</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:44 +0000</pubDate>
  </item>
  <item>
    <title>GraphQLer: Context-Aware GraphQL API Fuzzing Tool</title>
    <link>https://github.com/omar2535/GraphQLer</link>
    <guid isPermaLink="true">https://github.com/omar2535/GraphQLer</guid>
    <description>GraphQLer: Context-Aware GraphQL API Fuzzing Tool</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:43 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL Query Depth</title>
    <link>https://checkmarx.com/blog/exploiting-graphql-query-depth/</link>
    <guid isPermaLink="true">https://checkmarx.com/blog/exploiting-graphql-query-depth/</guid>
    <description>Exploiting GraphQL Query Depth</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:42 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting Broken Authentication Control in GraphQL</title>
    <link>https://www.praetorian.com/blog/exploiting-broken-authentication-control-graphql/</link>
    <guid isPermaLink="true">https://www.praetorian.com/blog/exploiting-broken-authentication-control-graphql/</guid>
    <description>Exploiting Broken Authentication Control in GraphQL</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:42 +0000</pubDate>
  </item>
  <item>
    <title>Didn&#x27;t Notice Your Rate Limiting: GraphQL Batching Attack</title>
    <link>https://checkmarx.com/blog/didnt-notice-your-rate-limiting-graphql-batching-attack/</link>
    <guid isPermaLink="true">https://checkmarx.com/blog/didnt-notice-your-rate-limiting-graphql-batching-attack/</guid>
    <description>Didn&#x27;t Notice Your Rate Limiting: GraphQL Batching Attack</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:41 +0000</pubDate>
  </item>
  <item>
    <title>Avoid GraphQL Denial-of-Service Attacks through Batching and Aliasing</title>
    <link>https://escape.tech/blog/graphql-batch-attacks-cause-dos/</link>
    <guid isPermaLink="true">https://escape.tech/blog/graphql-batch-attacks-cause-dos/</guid>
    <description>Avoid GraphQL Denial-of-Service Attacks through Batching and Aliasing</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:40 +0000</pubDate>
  </item>
  <item>
    <title>API Threat Research: GraphQL Authorization Flaws in a FinTech Platform</title>
    <link>https://salt.security/blog/api-threat-research-graphql-authorization-flaws-in-financial-technology-platform</link>
    <guid isPermaLink="true">https://salt.security/blog/api-threat-research-graphql-authorization-flaws-in-financial-technology-platform</guid>
    <description>API Threat Research: GraphQL Authorization Flaws in a FinTech Platform</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:39 +0000</pubDate>
  </item>
  <item>
    <title>Apollo Router Query Planner Excessive Resource Consumption via Named Fragment Expansion (CVE-2025-32034)</title>
    <link>https://github.com/advisories/GHSA-75m2-jhh5-j5g2</link>
    <guid isPermaLink="true">https://github.com/advisories/GHSA-75m2-jhh5-j5g2</guid>
    <description>Apollo Router Query Planner Excessive Resource Consumption via Named Fragment Expansion (CVE-2025-32034)</description>
    <category>GraphQL</category>
    <pubDate>Wed, 22 Apr 2026 12:50:39 +0000</pubDate>
  </item>
  <item>
    <title>PayloadsAllTheThings — GraphQL Injection</title>
    <link>https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection</link>
    <guid isPermaLink="true">https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/GraphQL%20Injection</guid>
    <description>PayloadsAllTheThings — GraphQL Injection</description>
    <category>GraphQL</category>
    <pubDate>Sun, 19 Apr 2026 02:38:41 +0000</pubDate>
  </item>
  <item>
    <title>Approaching GraphQL End Points — Bug Bounty Notes</title>
    <link>https://0xayub.gitbook.io/blog/approaching-graphql-end-points</link>
    <guid isPermaLink="true">https://0xayub.gitbook.io/blog/approaching-graphql-end-points</guid>
    <description>Approaching GraphQL End Points — Bug Bounty Notes</description>
    <category>GraphQL</category>
    <pubDate>Sun, 19 Apr 2026 02:36:49 +0000</pubDate>
  </item>
  <item>
    <title>DoS via Mutation Aliasing in GraphQL — HackerOne Disclosure</title>
    <link>https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-dos-via-mutation-aliasing-in-graphql-account-recovery-phone-number-verification-api-hellokbit/</link>
    <guid isPermaLink="true">https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-dos-via-mutation-aliasing-in-graphql-account-recovery-phone-number-verification-api-hellokbit/</guid>
    <description>DoS via Mutation Aliasing in GraphQL — HackerOne Disclosure</description>
    <category>GraphQL</category>
    <pubDate>Sun, 19 Apr 2026 02:36:48 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL API Vulnerabilities Learning Path — PortSwigger</title>
    <link>https://portswigger.net/web-security/learning-paths/graphql-api-vulnerabilities</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/learning-paths/graphql-api-vulnerabilities</guid>
    <description>GraphQL API Vulnerabilities Learning Path — PortSwigger</description>
    <category>GraphQL</category>
    <pubDate>Sun, 19 Apr 2026 02:21:36 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Introspection Security: Lessons from the Parse Server Vulnerability</title>
    <link>https://escape.tech/blog/lessons-from-the-parse-server-vulnerability/</link>
    <guid isPermaLink="true">https://escape.tech/blog/lessons-from-the-parse-server-vulnerability/</guid>
    <description>GraphQL Introspection Security: Lessons from the Parse Server Vulnerability</description>
    <category>GraphQL</category>
    <pubDate>Sun, 19 Apr 2026 02:21:35 +0000</pubDate>
  </item>
  <item>
    <title>Hasura GraphQL 1.3.3 Local File Read via SQL Injection</title>
    <link>https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection</link>
    <guid isPermaLink="true">https://www.vulncheck.com/advisories/hasura-graphql-local-file-read-via-sql-injection</guid>
    <description>Hasura GraphQL 1.3.3 Local File Read via SQL Injection</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:53 +0000</pubDate>
  </item>
  <item>
    <title>Discovering GraphQL endpoints and SQLi vulnerabilities</title>
    <link>https://medium.com/@localh0t/discovering-graphql-endpoints-and-sqli-vulnerabilities-5d39f26cea2e</link>
    <guid isPermaLink="true">https://medium.com/@localh0t/discovering-graphql-endpoints-and-sqli-vulnerabilities-5d39f26cea2e</guid>
    <description>Discovering GraphQL endpoints and SQLi vulnerabilities</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:52 +0000</pubDate>
  </item>
  <item>
    <title>HackerOne Report #435066: SQL injection in GraphQL endpoint</title>
    <link>https://hackerone.com/reports/435066</link>
    <guid isPermaLink="true">https://hackerone.com/reports/435066</guid>
    <description>HackerOne Report #435066: SQL injection in GraphQL endpoint</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:51 +0000</pubDate>
  </item>
  <item>
    <title>Prisma and PostgreSQL vulnerable to NoSQL injection? (Aikido)</title>
    <link>https://www.aikido.dev/blog/prisma-and-postgresql-vulnerable-to-nosql-injection</link>
    <guid isPermaLink="true">https://www.aikido.dev/blog/prisma-and-postgresql-vulnerable-to-nosql-injection</guid>
    <description>Prisma and PostgreSQL vulnerable to NoSQL injection? (Aikido)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:50 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Security: 9 Best Practices to Protect Your API (Escape)</title>
    <link>https://escape.tech/blog/9-graphql-security-best-practices/</link>
    <guid isPermaLink="true">https://escape.tech/blog/9-graphql-security-best-practices/</guid>
    <description>GraphQL Security: 9 Best Practices to Protect Your API (Escape)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:50 +0000</pubDate>
  </item>
  <item>
    <title>Authorization in GraphQL (Apollo)</title>
    <link>https://www.apollographql.com/blog/authorization-in-graphql</link>
    <guid isPermaLink="true">https://www.apollographql.com/blog/authorization-in-graphql</guid>
    <description>Authorization in GraphQL (Apollo)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:49 +0000</pubDate>
  </item>
  <item>
    <title>9 Ways To Secure your GraphQL API - Apollo Checklist</title>
    <link>https://www.apollographql.com/blog/9-ways-to-secure-your-graphql-api-security-checklist</link>
    <guid isPermaLink="true">https://www.apollographql.com/blog/9-ways-to-secure-your-graphql-api-security-checklist</guid>
    <description>9 Ways To Secure your GraphQL API - Apollo Checklist</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:48 +0000</pubDate>
  </item>
  <item>
    <title>Enforcing GraphQL security best practices with GraphOS</title>
    <link>https://www.apollographql.com/blog/enforcing-graphql-security-best-practices-with-graphos</link>
    <guid isPermaLink="true">https://www.apollographql.com/blog/enforcing-graphql-security-best-practices-with-graphos</guid>
    <description>Enforcing GraphQL security best practices with GraphOS</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:47 +0000</pubDate>
  </item>
  <item>
    <title>Apollo Authentication and Authorization Docs</title>
    <link>https://www.apollographql.com/docs/apollo-server/security/authentication</link>
    <guid isPermaLink="true">https://www.apollographql.com/docs/apollo-server/security/authentication</guid>
    <description>Apollo Authentication and Authorization Docs</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:47 +0000</pubDate>
  </item>
  <item>
    <title>Securing GraphQL API endpoints using rate limits and depth limits (LogRocket)</title>
    <link>https://blog.logrocket.com/securing-graphql-api-using-rate-limits-and-depth-limits/</link>
    <guid isPermaLink="true">https://blog.logrocket.com/securing-graphql-api-using-rate-limits-and-depth-limits/</guid>
    <description>Securing GraphQL API endpoints using rate limits and depth limits (LogRocket)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:07 +0000</pubDate>
  </item>
  <item>
    <title>Cyclic Queries and Depth Limiting (Escape)</title>
    <link>https://escape.tech/blog/cyclic-queries-and-depth-limit/</link>
    <guid isPermaLink="true">https://escape.tech/blog/cyclic-queries-and-depth-limit/</guid>
    <description>Cyclic Queries and Depth Limiting (Escape)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:07 +0000</pubDate>
  </item>
  <item>
    <title>IDOR Vulnerability In GraphQL Api On inmobi.com</title>
    <link>https://1mirabbas.medium.com/idor-vulnerability-in-graphql-api-on-inmobi-com-2482e3dfccf0</link>
    <guid isPermaLink="true">https://1mirabbas.medium.com/idor-vulnerability-in-graphql-api-on-inmobi-com-2482e3dfccf0</guid>
    <description>IDOR Vulnerability In GraphQL Api On inmobi.com</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:06 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL: Complete Guide for Bug Bounty Hunters</title>
    <link>https://medium.com/@M00xy/exploiting-graphql-a-complete-guide-for-bug-bounty-hunters-355fecb02eb0</link>
    <guid isPermaLink="true">https://medium.com/@M00xy/exploiting-graphql-a-complete-guide-for-bug-bounty-hunters-355fecb02eb0</guid>
    <description>Exploiting GraphQL: Complete Guide for Bug Bounty Hunters</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:05 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL for fun and bounties (BugBase)</title>
    <link>https://bugbase.ai/blog/exploiting-graphql-for-fun-and-bounties</link>
    <guid isPermaLink="true">https://bugbase.ai/blog/exploiting-graphql-for-fun-and-bounties</guid>
    <description>Exploiting GraphQL for fun and bounties (BugBase)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:04 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL for Bug Bounty (Mudhalai Mr)</title>
    <link>https://medium.com/dsc-sastra-deemed-to-be-university/graphql-for-bug-bounty-48e669963d90</link>
    <guid isPermaLink="true">https://medium.com/dsc-sastra-deemed-to-be-university/graphql-for-bug-bounty-48e669963d90</guid>
    <description>GraphQL for Bug Bounty (Mudhalai Mr)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:04 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL IDOR leads to information disclosure (Eshan Singh)</title>
    <link>https://medium.com/bugbountywriteup/graphql-idor-leads-to-information-disclosure-175eb560170d</link>
    <guid isPermaLink="true">https://medium.com/bugbountywriteup/graphql-idor-leads-to-information-disclosure-175eb560170d</guid>
    <description>GraphQL IDOR leads to information disclosure (Eshan Singh)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:03 +0000</pubDate>
  </item>
  <item>
    <title>Bug Bounty: BAC in GraphQL (10 Major Vulns - Cloverleaf)</title>
    <link>https://medium.com/@maakthon/bug-bounty-findings-10-major-vulnerabilities-exposed-in-cloverleafs-application-bac-in-graphql-0ae1ee0eb4d5</link>
    <guid isPermaLink="true">https://medium.com/@maakthon/bug-bounty-findings-10-major-vulnerabilities-exposed-in-cloverleafs-application-bac-in-graphql-0ae1ee0eb4d5</guid>
    <description>Bug Bounty: BAC in GraphQL (10 Major Vulns - Cloverleaf)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:02 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL for Penetration Testing (Raxis)</title>
    <link>https://raxis.com/blog/exploiting-graphql/</link>
    <guid isPermaLink="true">https://raxis.com/blog/exploiting-graphql/</guid>
    <description>Exploiting GraphQL for Penetration Testing (Raxis)</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:01 +0000</pubDate>
  </item>
  <item>
    <title>OWASP WSTG: Testing GraphQL</title>
    <link>https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/12-API_Testing/01-Testing_GraphQL</link>
    <guid isPermaLink="true">https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/12-API_Testing/01-Testing_GraphQL</guid>
    <description>OWASP WSTG: Testing GraphQL</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:01 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL Vulnerabilities: Misconfig to Data Leaks</title>
    <link>https://dev.to/cyberw1ng/exploiting-graphql-vulnerabilities-how-misconfigurations-can-lead-to-data-leaks-1dgp</link>
    <guid isPermaLink="true">https://dev.to/cyberw1ng/exploiting-graphql-vulnerabilities-how-misconfigurations-can-lead-to-data-leaks-1dgp</guid>
    <description>Exploiting GraphQL Vulnerabilities: Misconfig to Data Leaks</description>
    <category>GraphQL</category>
    <pubDate>Fri, 17 Apr 2026 14:42:00 +0000</pubDate>
  </item>
  <item>
    <title>BatchQL: GraphQL Security Auditing for Batch Attacks</title>
    <link>https://github.com/assetnote/batchql</link>
    <guid isPermaLink="true">https://github.com/assetnote/batchql</guid>
    <description>BatchQL: GraphQL Security Auditing for Batch Attacks</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:48 +0000</pubDate>
  </item>
  <item>
    <title>InQL: Advanced GraphQL Security Testing Burp Extension</title>
    <link>https://github.com/doyensec/inql</link>
    <guid isPermaLink="true">https://github.com/doyensec/inql</guid>
    <description>InQL: Advanced GraphQL Security Testing Burp Extension</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:47 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting CSRF in GraphQL Applications</title>
    <link>https://fdzdev.medium.com/exploiting-csrf-in-graphql-applications-f262411588f7</link>
    <guid isPermaLink="true">https://fdzdev.medium.com/exploiting-csrf-in-graphql-applications-f262411588f7</guid>
    <description>Exploiting CSRF in GraphQL Applications</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:46 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Vulnerabilities Cheat Sheet</title>
    <link>https://0xn3va.gitbook.io/cheat-sheets/web-application/graphql-vulnerabilities</link>
    <guid isPermaLink="true">https://0xn3va.gitbook.io/cheat-sheets/web-application/graphql-vulnerabilities</guid>
    <description>GraphQL Vulnerabilities Cheat Sheet</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:46 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL (Assetnote Research)</title>
    <link>https://www.assetnote.io/resources/research/exploiting-graphql</link>
    <guid isPermaLink="true">https://www.assetnote.io/resources/research/exploiting-graphql</guid>
    <description>Exploiting GraphQL (Assetnote Research)</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:45 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Discovery: Pentesting 101 Guide</title>
    <link>https://escape.tech/blog/pentest101/</link>
    <guid isPermaLink="true">https://escape.tech/blog/pentest101/</guid>
    <description>GraphQL Discovery: Pentesting 101 Guide</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:44 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Pentesting: Beginner&#x27;s Guide to Advanced</title>
    <link>https://medium.com/@m14r41/graphql-pentesting-a-beginners-guide-to-advanced-08c29bf82979</link>
    <guid isPermaLink="true">https://medium.com/@m14r41/graphql-pentesting-a-beginners-guide-to-advanced-08c29bf82979</guid>
    <description>GraphQL Pentesting: Beginner&#x27;s Guide to Advanced</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:44 +0000</pubDate>
  </item>
  <item>
    <title>The Complete GraphQL Security Guide: Fixing the 13 Most Common Vulnerabilities</title>
    <link>https://wundergraph.com/blog/the_complete_graphql_security_guide_fixing_the_13_most_common_graphql_vulnerabilities_to_make_your_api_production_ready</link>
    <guid isPermaLink="true">https://wundergraph.com/blog/the_complete_graphql_security_guide_fixing_the_13_most_common_graphql_vulnerabilities_to_make_your_api_production_ready</guid>
    <description>The Complete GraphQL Security Guide: Fixing the 13 Most Common Vulnerabilities</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:43 +0000</pubDate>
  </item>
  <item>
    <title>Abusing GraphQL Introspection: A Gateway for Recon and Exploitation</title>
    <link>https://infosecwriteups.com/abusing-graphql-introspection-a-gateway-for-recon-and-exploitation-ab5440ee6ade</link>
    <guid isPermaLink="true">https://infosecwriteups.com/abusing-graphql-introspection-a-gateway-for-recon-and-exploitation-ab5440ee6ade</guid>
    <description>Abusing GraphQL Introspection: A Gateway for Recon and Exploitation</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:42 +0000</pubDate>
  </item>
  <item>
    <title>Exploiting GraphQL: A Full-Spectrum Security Assessment</title>
    <link>https://kizerh.medium.com/exploiting-graphql-a-full-spectrum-security-assessment-covering-introspection-injection-and-560f49a44f36</link>
    <guid isPermaLink="true">https://kizerh.medium.com/exploiting-graphql-a-full-spectrum-security-assessment-covering-introspection-injection-and-560f49a44f36</guid>
    <description>Exploiting GraphQL: A Full-Spectrum Security Assessment</description>
    <category>GraphQL</category>
    <pubDate>Thu, 16 Apr 2026 21:03:41 +0000</pubDate>
  </item>
  <item>
    <title>Common Attacks on REST APIs and GraphQL APIs</title>
    <link>https://medium.com/@aniketdas07770/common-attacks-on-rest-apis-and-graphql-apis-with-tools-learning-resources-3c23c364467b</link>
    <guid isPermaLink="true">https://medium.com/@aniketdas07770/common-attacks-on-rest-apis-and-graphql-apis-with-tools-learning-resources-3c23c364467b</guid>
    <description>Common Attacks on REST APIs and GraphQL APIs</description>
    <category>GraphQL</category>
    <pubDate>Fri, 10 Apr 2026 01:55:43 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL API Security: Common Vulnerabilities and Exploits</title>
    <link>https://medium.com/@cybersec_cynoxsecurity/graphql-api-security-common-vulnerabilities-and-exploits-8efa8e463657</link>
    <guid isPermaLink="true">https://medium.com/@cybersec_cynoxsecurity/graphql-api-security-common-vulnerabilities-and-exploits-8efa8e463657</guid>
    <description>GraphQL API Security: Common Vulnerabilities and Exploits</description>
    <category>GraphQL</category>
    <pubDate>Fri, 10 Apr 2026 01:55:42 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL Security Testing: Introspection Abuse, Injection, and DoS</title>
    <link>https://www.redteamworldwide.com/graphql-api-security-testing/</link>
    <guid isPermaLink="true">https://www.redteamworldwide.com/graphql-api-security-testing/</guid>
    <description>GraphQL Security Testing: Introspection Abuse, Injection, and DoS</description>
    <category>GraphQL</category>
    <pubDate>Fri, 10 Apr 2026 01:55:41 +0000</pubDate>
  </item>
  <item>
    <title>Hacking (and Securing) GraphQL</title>
    <link>https://blog.arcjet.com/hacking-and-securing-graphql/</link>
    <guid isPermaLink="true">https://blog.arcjet.com/hacking-and-securing-graphql/</guid>
    <description>Hacking (and Securing) GraphQL</description>
    <category>GraphQL</category>
    <pubDate>Fri, 10 Apr 2026 01:55:40 +0000</pubDate>
  </item>
  <item>
    <title>GraphQL API Vulnerabilities - PortSwigger</title>
    <link>https://portswigger.net/web-security/graphql</link>
    <guid isPermaLink="true">https://portswigger.net/web-security/graphql</guid>
    <description>GraphQL API Vulnerabilities - PortSwigger</description>
    <category>GraphQL</category>
    <pubDate>Fri, 10 Apr 2026 01:43:18 +0000</pubDate>
  </item>
</channel>
</rss>