CVE-2026-104852: GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`
Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600
A client can alias fields to constructor, proto or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.proto to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.
graphql { shared { fieldA constructor: fieldB { proto: child { call: value } } } }
Other sources
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 12.0.1, the GraphQL Tools utils package's mergeDeep function follows inherited properties while recursively merging source objects and does not exclude proto, constructor, or prototype keys. An unauthenticated GraphQL client can alias fields to those names so responses from two subgraphs collide during ordinary supergraph result merging, causing mergeDeep to traverse Object and Function prototypes and overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests in the process until restart. This issue is fixed in version 12.0.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@graphql-tools/utilsto a version that resolves this vulnerability.Fixed in 12.0.1 - Upgrade
Upgrade
GraphQL Tools utils packageto a version that resolves this vulnerability.Fixed in 12.0.1
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
Any supergraph that uses the affected result-merging behavior and merges an object returned by two subgraphs is exposed. Ordinary @shareable and entity scenarios meet this condition.
Does exploitation require authentication or user interaction?
No. An unauthenticated client can trigger the issue with a single GraphQL query, and no user interaction is required.
What is the practical impact of a successful exploit?
A crafted field-alias query can cause result merging to overwrite Function.prototype.call with a subgraph-supplied value. This breaks subsequent requests handled by that process until it is restarted, resulting in denial of service.
Which package versions are affected?
The issue affects versions of the GraphQL Tools utils package prior to 12.0.1.
What should operators do if they use Hive Gateway?
Hive Gateway has a mitigation referenced in pull request 2600. Operators should ensure their deployment includes that mitigation and restart a process if it has already been disrupted.