CVE-2026-104852: GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

Published Oct 5, 2026
·
Updated

Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600

A client can alias fields to constructor, proto or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.proto to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.

graphql { shared { fieldA constructor: fieldB { proto: child { call: value } } } }

Other sources

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude proto, constructor, or prototype keys. An unauthenticated GraphQL client can alias fields to those names so responses from two subgraphs collide during ordinary supergraph result merging, causing mergeDeep to traverse Object and Function prototypes and overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests in the process until restart. This issue is fixed in version 12.0.1.

— MITRE

Affected Software

2 affected componentsFixes available
npm/@graphql-tools/utils<12.0.1
npm/@graphql-tools/utils<=12.0.0
12.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@graphql-tools/utils to a version that resolves this vulnerability.

    Fixed in 12.0.1
  2. Upgrade

    Upgrade GraphQL Tools utils package to a version that resolves this vulnerability.

    Fixed in 12.0.1

Event History

Oct 5, 2026
CVE Published
via MITRE·10:56 PM
Data Sourced
via MITRE·10:56 PM
DescriptionWeakness
Advisory Published
via GitHub·10:56 PM
Data Sourced
via GitHub·10:56 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to remote exploitation?

Any supergraph that uses the affected result-merging behavior and merges an object returned by two subgraphs is exposed. Ordinary @shareable and entity scenarios meet this condition.

2

Does exploitation require authentication or user interaction?

No. An unauthenticated client can trigger the issue with a single GraphQL query, and no user interaction is required.

3

What is the practical impact of a successful exploit?

A crafted field-alias query can cause result merging to overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests handled by that process until it is restarted, resulting in denial of service.

4

Which package versions are affected?

The issue affects versions of the GraphQL Tools utils package prior to 12.0.1.

5

What should operators do if they use Hive Gateway?

Hive Gateway has a mitigation referenced in pull request 2600. Operators should ensure their deployment includes that mitigation and restart a process if it has already been disrupted.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203