GraphQL
GraphQL is a query language for APIs and a runtime for fulfilling those queries with your existing data. It gives clients the power to ask for exactly what they need, makes it easier to evolve APIs over time, and enables powerful developer tools.
From a security perspective, GraphQL introduces a unique attack surface that differs significantly from traditional REST APIs. Introspection queries can expose the entire schema — every type, field, and relationship — giving attackers a detailed map of the application's data model. Deeply nested queries enable denial-of-service through resource exhaustion, while batch queries can bypass rate limiting designed for REST endpoints.
Common GraphQL security issues include broken authorization on field-level resolvers, information disclosure through verbose error messages, and injection vulnerabilities in custom directives or filters. Many applications disable introspection in production but forget to restrict it in staging environments, or expose schema details through autocomplete suggestions.
Testing GraphQL requires specialized tools and techniques. Unlike REST APIs where endpoints are enumerable, GraphQL consolidates everything behind a single endpoint, requiring schema-aware fuzzing and query manipulation.
This page collects security research, testing methodologies, and real-world vulnerabilities specific to GraphQL APIs — from introspection abuse to authorization bypasses and injection attacks.
From graphql.org
GraphQL moves the bugs rather than removing them
A GraphQL endpoint is one URL that can express an enormous number of queries, and almost every security property people assume it has comes from the resolver layer rather than the protocol. Teams migrating from REST tend to port their authentication and lose their authorization, because in REST the route was the unit of access control and in GraphQL there are no routes.
Start with schema discovery. Introspection is the intended mechanism and is frequently left enabled in production; when it is disabled, field suggestion in error messages, persisted query listings and client bundles usually give up most of the schema anyway. Knowing the schema is what turns GraphQL testing from guesswork into reading — once you can see the types, you can see which edges connect user-controlled input to sensitive objects.
The authorization problems follow from nesting. A field that is properly protected at the top level is often reachable through a relation on another type, because the check was written on the query entry point rather than on the resolver that loads the data. This is the GraphQL form of IDOR, and it is more common than the REST version because the traversal paths are so much harder to enumerate by hand. Aliasing compounds it: the same field requested fifty times under fifty names in one document will defeat a rate limiter that counts requests.
Then there is cost. Nested and recursive queries let a small request produce enormous server work, and batching lets a single HTTP request carry many operations — which also turns a per-request brute-force limit into no limit at all. Depth limiting, query cost analysis and persisted queries are the standard answers, and the research below is largely about the gaps between them.
If you are testing one of these for the first time, the practical order is: recover the schema, map which types expose user or tenant data, test authorization on nested paths rather than root fields, then look at batching and aliasing for the rate-limit and enumeration work.
| Date Added | Link | Excerpt |
|---|---|---|
| 2026-09-03 2026 | "City-Forum" data-theft attacks target Salesforce ServiceNow portals news 4 min read | Library for identifying and preventing "City-Forum" data-theft attacks, which target misconfigured Salesforce Experience Cloud and ServiceNow customer portals. These attacks leverage unauthenticated guest user access to steal data via API endpoints, including Salesforce's Aura framework (/aura, /s/sfsites/aura) and newer Lightning Web Runtime (LWR) framework (/webruntime/api/services/data/{version}/graphql), as well as ServiceNow's POST /api/now/sp/search. The campaign, originating from IP address 158.220.87.79, abuses overly permissive sharing rules and portal configurations, distinct from past ShinyHunters campaigns by its singular infrastructure. → bleepingcomputer.com |
| 2026-08-26 2026 | Active Exploitation Alert: Critical GitLab CVE-2026-19478 Code Injection Vulnerability Targets Unpatched Instances news 4 min read | Analysis of CVE-2026-19478 details a critical code injection vulnerability affecting GitLab CE/EE, allowing unauthenticated attackers to manipulate public projects via crafted GraphQL directives like @gl_introduced. Exploitation is active, with threat actors rapidly weaponizing proof-of-concept code to delete projects, forge merge records, and ban maintainers. Immediate patching is recommended, with affected versions prior to 18.11.11, 19.0.8, 19.1.6, and 19.2.4. → rescana.com |
| 2026-08-25 2026 | Critical GitLab vulnerability exploited days after disclosure news 3 min read | Analysis of CVE-2026-19478 details the rapid exploitation of a critical GitLab vulnerability affecting self-managed Community Edition and Enterprise Edition deployments. This code injection flaw, with a CVSS score of 9.4, allows unauthenticated actors to modify or delete public projects and user data through a single HTTP request, impacting source code integrity and development operations. Affected versions require immediate patching to GitLab 18.11.11, 19.0.8, 19.1.6, or 19.2.4, with interim mitigations including access restrictions to the /api/graphql endpoint. |
| 2026-08-24 2026 | CVE-2026-19478: GitLab GraphQL Flaw Exploited news 2 min read | Writeup of CVE-2026-19478 details a critical GraphQL code injection vulnerability in self-managed GitLab CE/EE, allowing unauthenticated attackers to modify or delete public projects and user data via the @gl_introduced directive. This flaw, with a CVSS score of 9.4 (CWE-94), poses significant operational and supply chain risks. Exploitation attempts have been observed in the wild, necessitating immediate updates to patched versions like 18.11.11, 19.0.8, 19.1.6, or 19.2.4. → socradar.io |
| 2026-08-24 2026 | GitLab Warns of Active Exploitation of Critical GraphQL Flaw news 1 min read | Library for patching GitLab, addressing CVE-2026-19478, a critical GraphQL flaw allowing unauthenticated remote modification or deletion of public projects and user data. This vulnerability, with a CVSS score of 9.4, impacts self-managed installations and requires upgrades to specific patched versions. Mitigation includes restricting unauthenticated access to /api/graphql and disabling public repositories. → securityaffairs.com |
| 2026-08-21 2026 | GitLab Warns of Active Exploitation of Critical GraphQL Flaw news 1 min read | Library for mitigating CVE-2026-19478, a critical GitLab GraphQL vulnerability allowing unauthenticated remote modification or deletion of public projects and user data. Patches are available for specific versions, and mitigation strategies include restricting unauthenticated access to `/api/graphql` and disabling public repositories. → securityaffairs.com |
| 2026-08-21 2026 | GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure news 1 min read | Analysis of CVE-2026-19478, a critical code injection vulnerability in GitLab (CVSS 9.4), details active exploitation within days of disclosure. This flaw affects specific versions of GitLab Community Edition (CE) and Enterprise Edition (EE) and can be exploited via a GraphQL directive to modify, delete, or rewrite publicly accessible projects without authentication. Patched versions include 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Mitigation strategies include restricting unauthenticated access to "/api/graphql" or removing public repository access if immediate patching is not feasible. → thehackernews.com |
| 2026-08-20 2026 | GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability news 4 min read | Writeup on CVE-2026-19478, a critical GitLab vulnerability with a CVSS score of 9.4, enabling unauthenticated attackers to delete public repositories and alter project data via a GraphQL directive. Self-managed instances are at risk, with observed in-the-wild exploitation attempts. Compromise poses software supply chain risks by manipulating repositories, merge records, and maintainer access. Immediate patching is recommended, with temporary controls including restricting unauthenticated /api/graphql access and monitoring for suspicious activity. → esecurityplanet.com |
| 2026-08-19 2026 | Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive intermediate 5 min read | Library for securing GitLab's GraphQL API, addressing CVE-2026-19478, a critical code injection vulnerability allowing unauthenticated users to modify or delete public data, and CVE-2026-19650, a high-severity CSRF flaw enabling state-changing mutations via GET requests. Patches are available for self-managed instances. → ox.security |
| 2026-08-18 2026 | Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) news 1 min read | Writeup of CVE-2026-19478 in GitLab, a critical code injection flaw exploitable without authentication. This vulnerability, affecting GitLab CE/EE versions prior to specific patches, allows remote attackers to modify or delete public projects and user data. A secondary CSRF flaw, CVE-2026-19650, enables mutation execution via GET requests with user interaction. Both issues were reported via GitLab's HackerOne program. → helpnetsecurity.com |
| 2026-08-18 2026 | GitLab Patches Critical Code Injection Vulnerability news 1 min read | Library patches address CVE-2026-19478, a critical code injection vulnerability allowing unauthenticated attackers to modify or delete data via GraphQL directives, and CVE-2026-19650, a CSRF flaw in the GraphQL multiplex query handler. These vulnerabilities impact GitLab CE/EE versions 18.2, 19.0, 19.1, and 19.2 and onwards, with fixes available in specific patched versions. → securityweek.com |
| 2026-08-18 2026 | GitLab Patches Critical Unauthenticated GraphQL Vulnerability news 2 min read | Library update detailing GitLab's emergency patch for CVE-2026-19478, a critical unauthenticated GraphQL vulnerability (CVSS 9.4) allowing modification or deletion of public projects and data. The patch addresses self-managed installations and also includes a fix for CVE-2026-19650, a CSRF weakness in GraphQL multiplex queries (CVSS 7.1). Affected versions require upgrade to specific patched branches, as older releases within the affected range will not receive direct fixes. → securityaffairs.com |
| 2026-08-18 2026 | CVE-2026-19478: Critical GitLab CE/EE GraphQL Vulnerability Enables Remote Deletion of Public Projects and User Data news 3 min read | Writeup of CVE-2026-19478, a critical GitLab CE/EE GraphQL vulnerability, detailing how unauthenticated attackers can remotely delete or modify public projects and user data. This CVSS 9.4 flaw, affecting self-managed installations across specific versions (18.2 to 19.2.4), maps to MITRE ATT&CK techniques like Data Destruction (T1485) and Exploitation of Public-Facing Application (T1190). Immediate patching is advised, as exploitation is trivial and poses a severe risk of data loss. → rescana.com |
| 2026-08-17 2026 | Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects news 2 min read | Writeup of CVE-2026-19478, a critical GitLab vulnerability (CVSS 9.4) allowing unauthenticated attackers to delete or modify public projects via a GraphQL directive. This flaw impacts self-managed GitLab Community and Enterprise Editions versions prior to 19.2.4, 19.1.6, 19.0.8, and 18.11.11. A separate high-severity CSRF vulnerability (CVE-2026-19650) in GraphQL multiplex query handling also exists. → thehackernews.com |
| 2026-08-05 2026 | ZeroThreat.ai Challenges Traditional DAST With Application-Aware Security Testing beginner 3 min read | Library that provides application-aware security testing, challenging traditional DAST with AI-powered pentesting for modern, dynamic applications. It intelligently understands application behavior, navigates authenticated workflows, and executes multi-step user journeys across REST, GraphQL, SOAP, and gRPC APIs. The platform's validation-first approach reduces false positives by verifying exploitability before reporting vulnerabilities, offering deeper visibility and more actionable findings for developers and security professionals. |
| 2026-07-12 2026 | Ghost Accounts Abuse GitHub API in Mass Recon Campaign news 2 min read | Analysis of ghost account abuse of the GitHub API reveals mass reconnaissance campaigns leveraging dormant accounts and leaked credentials. Threat actors exploit unauthenticated API endpoints, including REST and GraphQL, to enumerate organizations, repositories, and users. While primarily focused on reconnaissance, some campaigns escalated to cloning repositories and exfiltrating data, sometimes using inadvertently exposed tokens. Detection strategies involve monitoring for data exfiltration from private repositories, anomalous user agent behavior, and establishing baselines for normal GitHub activity. → securityweek.com |
| 2026-07-02 2026 | What Is API Security? beginner 19 min read | Reference detailing common API security risks and vulnerabilities, including Security Misconfiguration (API8:2023), Broken Object Level Authorization (API1:2023), Unrestricted Access to Sensitive Business Flows (API6:2023), Unrestricted Resource Consumption (API4:2023), Unsafe Consumption of APIs (API10:2023), Server Side Request Forgery (API7:2023), Improper Inventory Management (API9:2023), Broken Object Property Level Authorization (API3:2023), Broken Function Level Authorization (API5:2023), and Broken Authentication (API2:2023). It also covers API security monitoring and cloud API security strategies for DevOps. → paloaltonetworks.com |
| 2026-06-30 2026 | The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API intermediate 6 min read AuthZ | Library for discovering and exploiting Broken Object-Level Authorization (BOLA) vulnerabilities in GraphQL APIs. This resource details a Red Agent's autonomous exploitation of an airline's booking API, demonstrating how predictable integer identifiers combined with a lack of backend authorization checks allowed for the mass extraction and modification of sensitive passenger data, including names, dates of birth, billing addresses, masked credit cards, and live flight itineraries. The exploit achieved full read and write capabilities over active travel plans within minutes, highlighting the inadequacy of traditional security tools against such logic flaws. → wiz.io |
| 2026-06-29 2026 | The Red Agent POV: Exploiting Broken Object-Level Authorization in an Airline GraphQL API intermediate 6 min read | Library for identifying Broken Object-Level Authorization (BOLA) vulnerabilities, exemplified by an airline's GraphQL booking API exploit. The Red Agent autonomously discovered mass data extraction and write capabilities by manipulating sequential booking IDs without backend authorization checks. This bypass allows unauthenticated access to passenger details, flight itineraries, and payment information, highlighting the critical need for strict object-level access controls on API resolvers. → wiz.io |
| 2026-06-19 2026 | CVE-2021-4191: GitLab GraphQL API User Enumeration (FIXED) news 5 min read | Writeup of CVE-2021-4191, a GitLab GraphQL API vulnerability, details how remote, unauthenticated attackers could enumerate usernames, names, and email addresses. This information leak, classified as CWE-359, enables attackers to build user lists for brute-force attacks and sophisticated phishing campaigns. The article discusses the vulnerability's introduction in GitLab versions 13.0, outlines exploitation methods via the `/api/graphql` endpoint, and provides a Python script for user enumeration. Mitigation advice includes patching GitLab instances and disabling public profiles. → rapid7.com |
| 2026-06-10 2026 | How GraphQL Mutation Aliasing Led to a $12,500 DoS Bug in HackerOne’s Account Recovery Flow intermediate Bug Bounty | A researcher discovered a Denial of Service (DoS) bug in HackerOne's account recovery process due to a feature in GraphQL called mutation aliasing. This behavior allowed an attacker to trigger multiple, recursive mutations, overwhelming the system and preventing legitimate users from recovering their accounts. HackerOne acknowledged the vulnerability and awarded the researcher $12,500 for their findings. → infosecwriteups.com |
| 2026-05-18 2026 | TanStack npm Packages Hit by Mini Shai-Hulud news 12 min read | Library for securing npm supply chains, detailing the "Mini Shai-Hulud" attack that compromised TanStack packages. This incident, attributed to TeamPCP, exploited a chained vulnerability involving GitHub Actions' `pull_request_target` trigger for cache poisoning and OIDC token extraction via memory dumping, resulting in malicious packages with SLSA provenance. The attack utilized an injected `router_init.js` payload executed via lifecycle hooks, affecting numerous downstream projects including Mistral AI and UiPath, with CVE-2026-45321 being a critical vulnerability. → snyk.io |
| 2026-04-22 2026 | CVE-2025-59845: CSRF Vulnerability in Apollo Studio Embeddable Explorer and Sandbox news 1 min read | Writeup of CVE-2025-59845, a high-severity CSRF vulnerability in Apollo Studio Embeddable Explorer and Sandbox. Exploiting a lack of origin validation for `window.postMessage` events, attackers can trick user browsers into executing arbitrary GraphQL queries against vulnerable servers, potentially leading to system compromise or data leakage. Organizations using affected versions prior to Apollo Sandbox 2.7.2 and Apollo Explorer 3.7.3 should apply vendor patches immediately. |
| 2026-04-22 2026 | CVE-2025-31496: GraphQL Query Vulnerability in Apollo Compiler Leading to DoS news 1 min read | Writeup of CVE-2025-31496, a denial-of-service vulnerability in the Apollo Compiler affecting versions prior to 1.27.0. The exploit leverages a flaw in how named fragments are handled during query validation, leading to exponential resource consumption when fragments are deeply nested and reused. Attackers can craft specific GraphQL queries to trigger this vulnerability, potentially causing system compromise or data leakage. |
| 2026-04-22 2026 | The 16-Hour Window: Catching a GraphQL Authorization Flaw intermediate | The 16-Hour Window: Catching a GraphQL Authorization Flaw |
| 2026-04-22 2026 | GraphQLer: Context-Aware GraphQL API Fuzzing Tool intermediate 7 min read | Tool for context-aware GraphQL API fuzzing. GraphQLer automatically reads API schemas, generates valid queries and mutations based on the schema and object dependencies, and tracks resources for reconnaissance. It can detect insecure direct object reference (IDOR) vulnerabilities using dual-profile chain replay and offers an interactive TUI for ease of use, with optional proxy support for Burp Suite or OWASP ZAP. |
| 2026-04-22 2026 | Exploiting GraphQL Query Depth intermediate 2 min read | Article on exploiting GraphQL query depth, demonstrating how nested object requests can lead to Denial of Service (DoS) attacks against applications like the Damn Vulnerable GraphQL Application. It highlights the performance degradation caused by deep recursion and references OWASP GraphQL Cheat Sheet and Apollo blog posts for remediation techniques such as setting timeouts, maximum depth, or query complexity thresholds. → checkmarx.com |
| 2026-04-22 2026 | Exploiting Broken Authentication Control in GraphQL intermediate 3 min read | Writeup of a privilege escalation vulnerability in a financial application's GraphQL API, demonstrating how broken authentication and authorization controls allowed an attacker to gain administrative privileges. The attack involved enumerating administrative usernames using Burp Suite Intruder and then substituting an authorized username into a `brassCheckAccess` query. Recommendations include validating usernames against requesting user session tokens and implementing directive constraints and middleware for input sanitization. |
| 2026-04-22 2026 | Didn't Notice Your Rate Limiting: GraphQL Batching Attack intermediate 6 min read | Writeup detailing the GraphQL Batching Attack, a vulnerability where improperly implemented rate limiting allows attackers to bypass restrictions. This attack leverages GraphQL's batching feature, enabling multiple queries within a single HTTP request, to perform actions like server-side object enumeration or brute-force attacks. The article demonstrates how an attacker can submit numerous login mutations simultaneously, bypassing per-request rate limits and potentially gaining unauthorized access, as seen in the example of cracking a password from a list of common ones. → checkmarx.com |
| 2026-04-22 2026 | Avoid GraphQL Denial-of-Service Attacks through Batching and Aliasing intermediate 3 min read | Library for securing GraphQL APIs, addressing denial-of-service (DoS) attacks and credential brute-forcing enabled by batching and aliases. Batch attacks bypass traditional rate limiting by executing numerous operations within a single API call, overwhelming servers and facilitating unauthorized access. This library, including the open-source GraphQL Armor plugin and a specialized scanner, helps identify and mitigate these vulnerabilities by enforcing query validation and limiting alias usage. → escape.tech |
| 2026-04-22 2026 | API Threat Research: GraphQL Authorization Flaws in a FinTech Platform intermediate | API Threat Research: GraphQL Authorization Flaws in a FinTech Platform |
| 2026-04-22 2026 | Apollo Router Query Planner Excessive Resource Consumption via Named Fragment Expansion (CVE-2025-32034) news | Library patch addressing CVE-2025-32034 in Apollo Router, which allowed excessive resource consumption via named fragment expansion during query planning. The vulnerability stemmed from fragments being expanded exponentially with deep nesting. The fix introduces a Query Fragment Expansion Limit metric to cap computation, with remediation available in apollo-router versions 1.61.2 and 2.1.1. A workaround involves safelisting queries. |
| 2026-04-19 2026 | PayloadsAllTheThings — GraphQL Injection intermediate 9 min read | Library for GraphQL injection attacks, detailing introspection queries and tools like `GraphQLmap`, `inql`, and `CrackQL`. It covers techniques for enumerating schema details, identifying entry points to specific types using `graphql-path-enum`, and discovering API endpoints like `/graphql` and `/graphiql`. The library also provides strategies for handling disabled introspection and brute-forcing keywords with wordlists. |
| 2026-04-19 2026 | Approaching GraphQL End Points — Bug Bounty Notes intermediate | Approaching GraphQL End Points — Bug Bounty Notes |
| 2026-04-19 2026 | DoS via Mutation Aliasing in GraphQL — HackerOne Disclosure intermediate 2 min read | Writeup detailing a Denial-of-Service (DoS) vulnerability in a HackerOne-reported GraphQL API, specifically targeting account recovery phone number verification. The flaw arises from mutation aliasing, allowing a single request to execute the `verifyAccountRecoveryPhoneNumber` mutation multiple times, leading to server-side resource exhaustion and service degradation for legitimate users. Recommendations include implementing hard caps on mutation aliases and per-request quotas for expensive operations. |
| 2026-04-19 2026 | GraphQL API Vulnerabilities Learning Path — PortSwigger beginner | GraphQL API Vulnerabilities Learning Path — PortSwigger → portswigger.net |
| 2026-04-19 2026 | GraphQL Introspection Security: Lessons from the Parse Server Vulnerability intermediate 4 min read | Reference on GraphQL introspection security, lessons learned from CVE-2025-53364 in Parse Server, highlights that disabling introspection is not a comprehensive solution. The vulnerability allowed public schema access, aiding targeted attacks. Secure introspection through authentication and RBAC, avoiding public exposure. While useful for development and public APIs, introspection can be bypassed via field suggestion or traffic analysis. Consider disabling it for private APIs if not needed, but otherwise focus on controlled access and automated testing with tools like Escape. → escape.tech |
| 2026-04-17 2026 | Hasura GraphQL 1.3.3 Local File Read via SQL Injection intermediate | Advisory detailing a local file read vulnerability in Hasura GraphQL 1.3.3, exploitable via SQL injection. Attackers can leverage the `pg_read_file()` function through crafted queries on the query endpoint to access arbitrary files on the server, impacting systems running this version. |
| 2026-04-17 2026 | Discovering GraphQL endpoints and SQLi vulnerabilities intermediate | Discovering GraphQL endpoints and SQLi vulnerabilities |
| 2026-04-17 2026 | HackerOne Report #435066: SQL injection in GraphQL endpoint news | HackerOne Report #435066: SQL injection in GraphQL endpoint → hackerone.com |
| 2026-04-17 2026 | Prisma and PostgreSQL vulnerable to NoSQL injection? (Aikido) intermediate 4 min read | Library vulnerability analysis demonstrating how Prisma ORM, even with PostgreSQL, is susceptible to operator injection, commonly known as NoSQL injection. This occurs when user input is passed to query functions supporting string-based operators, such as `findFirst`, `findMany`, `updateMany`, and `deleteMany`. The analysis highlights exploits and recommends prevention techniques including casting user input to primitive data types, implementing robust server-side validation with libraries like Zod, and keeping ORMs like Prisma and Sequelize updated to benefit from security fixes. → aikido.dev |
| 2026-04-17 2026 | GraphQL Security: 9 Best Practices to Protect Your API (Escape) beginner 9 min read | Library for protecting GraphQL APIs from common vulnerabilities. It details techniques for disabling introspection, implementing robust authorization and authentication at the resolver level, and mitigating denial-of-service attacks through query whitelisting, depth limiting, and complexity analysis. Examples include using Apollo Server with `introspection: process.env.NODE_ENV !== 'production'`, implementing `authMiddleware`, and utilizing libraries like `graphql-depth-limit`. → escape.tech |
| 2026-04-17 2026 | Authorization in GraphQL (Apollo) intermediate 9 min read | Reference on authorization in GraphQL via Apollo, covering authentication versus authorization, obtaining user data from requests, schema-level authorization by throwing errors in the context function, and granular authorization within resolvers by checking user roles before returning data or calling data retrieval functions. |
| 2026-04-17 2026 | 9 Ways To Secure your GraphQL API - Apollo Checklist beginner 10 min read | Checklist of 9 security measures for GraphQL APIs, detailing strategies for authentication and authorization using JWTs, reducing attack surface area by limiting query depth with `graphql-depth-limit`, paginating list fields, improving input validation and sanitization, implementing timeouts, rate limiting, query cost analysis, and safelisting operations via automatic persisted queries. It also covers limiting API discoverability by disabling introspection in production. |
| 2026-04-17 2026 | Enforcing GraphQL security best practices with GraphOS beginner 4 min read | Library for enforcing GraphQL security best practices with GraphOS. This library enables centralized authorization in the router, safelisting registered operations to reduce surface area, and limiting operation complexity via depth, height, aliases, and root fields. It leverages directives like `@requiresScopes` and `@authenticated` for declarative access control, and supports JWT authentication for adding claims to request contexts. |
| 2026-04-17 2026 | Apollo Authentication and Authorization Docs beginner 10 min read | Library for implementing authentication and authorization in GraphQL APIs, demonstrating how to extract user tokens from HTTP headers, populate the `contextValue` with user information, and implement API-wide or field-level access control using roles. The documentation covers techniques for denying access via `GraphQLError` and conditionally returning data within resolvers based on user authentication status. |
| 2026-04-17 2026 | Securing GraphQL API endpoints using rate limits and depth limits (LogRocket) intermediate 9 min read | Library implementing rate and depth limiting for Node.js GraphQL APIs. This library leverages Redis for storing rate-limiting data and offers directives to apply limits directly within your GraphQL schema. It supports identifying clients by IP address or other unique identifiers, customizes error messages when limits are exceeded, and integrates with GraphQL servers like GraphQL Yoga and Apollo. → blog.logrocket.com |
| 2026-04-17 2026 | Cyclic Queries and Depth Limiting (Escape) intermediate 7 min read | Library for mitigating denial-of-service attacks against GraphQL APIs by limiting query depth and execution time. It details how malicious queries can exploit cyclic relationships in graph databases, leading to performance degradation and resource exhaustion. The library, through tools like `graphql-depth-limit` for Apollo, Express GraphQL, and GraphQL Node, and configuration options for Hasura Cloud and Graphene, enables developers to set maximum query depths and timeouts, ensuring application stability while maintaining usability. → escape.tech |
| 2026-04-17 2026 | IDOR Vulnerability In GraphQL Api On inmobi.com intermediate | IDOR Vulnerability In GraphQL Api On inmobi.com |
| 2026-04-17 2026 | Exploiting GraphQL: Complete Guide for Bug Bounty Hunters beginner | Exploiting GraphQL: Complete Guide for Bug Bounty Hunters |
| Browse all 117 GraphQL resources → | ||
Frequently Asked Questions
- How is GraphQL security different from REST?
- GraphQL consolidates all operations behind a single endpoint, making traditional API enumeration ineffective. Unique risks include schema introspection exposure, deeply nested query denial-of-service, batch query abuse to bypass rate limiting, and field-level authorization gaps in resolvers.
- Should you disable GraphQL introspection in production?
- Yes, disabling introspection in production is a recommended security practice. It prevents attackers from mapping your entire schema, including types, fields, and relationships. However, schema details can still leak through error messages, autocomplete, and field suggestion features.
- What tools are used to test GraphQL security?
- Common tools include GraphQL Voyager for schema visualization, InQL for Burp Suite integration, graphql-cop for automated security testing, and Clairvoyance for schema reconstruction when introspection is disabled. Manual testing with crafted queries remains essential.
Weekly AppSec Digest
Get new resources delivered every Monday.