Closed by https://github.com/ardatan/graphql-tools/pull/8423 Mitigated in Hive Gateway by https://github.com/graphql-hive/gateway/pull/2600
A client can alias fields to constructor, proto or prototype so that the response keys from two subgraphs collide on those names during result merging. Because mergeDeep recursed through inherited properties, the merge walked {}.constructor to Object, then Object.proto to Function.prototype, and wrote a subgraph-supplied value over Function.prototype.call, breaking every subsequent request in the process until restart. This is remotely triggerable by an unauthenticated client with a single query against any supergraph that merges an object from two subgraphs, which is the ordinary @shareable or entity case, so it is a denial of service rather than a theoretical hardening issue.
graphql { shared { fieldA constructor: fieldB { proto: child { call: value } } } }