juniper
Activity
- Latest release
- 7mo ago
- Total releases
- 41
- Cadence
- ~38 days
- Last 12 months
- 1
Details
- License
- BSD-2-Clause
- First release
- Sep 11, 2016
| Version | Released | |
|---|---|---|
0.17.1
unknown
|
0.17.1
unknown
Dependencies (39)
+ 31 more |
|
0.17.0
unknown
|
0.17.0
unknown
Dependencies (39)
+ 31 more |
|
0.16.2
unknown
|
0.16.2
unknown
Dependencies (31)
+ 23 more |
|
0.16.1
unknown
|
0.16.1
unknown
Dependencies (31)
+ 23 more |
|
0.16.0
unknown
|
0.16.0
unknown
Dependencies (31)
+ 23 more |
|
0.15.12
unknown
|
0.15.12
unknown
Dependencies (21)
+ 13 more |
|
0.15.11
unknown
|
0.15.11
unknown
Dependencies (21)
+ 13 more |
|
0.15.10
unknown
|
0.15.10
unknown
Dependencies (21)
+ 13 more |
|
0.15.9
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.9
unknown
Dependencies (21)
+ 13 more |
|
0.15.8
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.8
unknown
Dependencies (21)
+ 13 more |
|
0.15.7
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.7
unknown
Dependencies (21)
+ 13 more |
|
0.15.6
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.6
unknown
Dependencies (21)
+ 13 more |
|
0.15.5
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.5
unknown
Dependencies (21)
+ 13 more |
|
0.15.4
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.4
unknown
Dependencies (21)
+ 13 more |
|
0.15.3
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.3
unknown
Dependencies (20)
+ 12 more |
|
0.15.2
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.2
unknown
Dependencies (20)
+ 12 more |
|
0.15.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.1
unknown
Dependencies (20)
+ 12 more |
|
0.15.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.15.0
unknown
Dependencies (20)
+ 12 more |
|
0.14.2
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.14.2
unknown
Dependencies (11)
+ 3 more |
|
0.14.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.14.1
unknown
Dependencies (11)
+ 3 more |
|
0.14.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (11)
+ 3 more |
|
0.13.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.13.1
unknown
Dependencies (11)
+ 3 more |
|
0.13.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (11)
+ 3 more |
|
0.12.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.12.0
unknown
Dependencies (11)
+ 3 more |
|
0.11.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.11.1
unknown
Dependencies (11)
+ 3 more |
|
0.11.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.11.0
unknown
Dependencies (11)
+ 3 more |
|
0.10.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.10.0
unknown
Dependencies (11)
+ 3 more |
|
0.9.2
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.9.2
unknown
Dependencies (11)
+ 3 more |
|
0.9.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.9.1
unknown
Dependencies (11)
+ 3 more |
|
0.9.0
unknown
yanked
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.9.0
unknown
yanked
Dependencies (11)
+ 3 more |
|
0.8.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.8.1
unknown
Dependencies (13)
+ 5 more |
|
0.8.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.8.0
unknown
Dependencies (13)
+ 5 more |
|
0.7.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (9)
+ 1 more |
|
0.6.3
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.6.3
unknown
Dependencies (9)
+ 1 more |
|
0.6.2
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.6.2
unknown
Dependencies (9)
+ 1 more |
|
0.6.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.6.1
unknown
Dependencies (9)
+ 1 more |
|
0.6.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (8)
|
|
0.5.3
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (7)
|
|
0.5.2
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (7)
|
|
0.5.1
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.5.1
unknown
Dependencies (7)
|
|
0.5.0
unknown
1 CVE
CVE-2022-31173
GHSA-4rx6-g5vg-5f3j
RUSTSEC-2022-0038
Jul 29, 2022
Juniper is vulnerable to @DOS GraphQL Nested Fragments overflow
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
GraphQL behaviourNested fragment in GraphQL might be quite hard to handle depending on the implementation language. Some language support natively a max recursion depth. However, on most compiled languages, you should add a threshold of recursion.
POC TLDRWith max_size being the number of nested fragment generated. At max_size=7500, it should instantly raise:
However, with a lower size, you will overflow the memory after some iterations. Reproduction steps (Juniper)
Save this POC as poc.py
Credits@c3b5aw @MdotTIM @karimhreda Fixed in
0.15.10
References
Updated Feb 04, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (7)
|
