{"id":"CVE-2021-43801","aliases":["GHSA-273r-rm8g-7f3x"],"url":"https://o3.security/vulnerability/CVE-2021-43801","summary":"Uncaught Exception in mercurius","details":"Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in https://github.com/mercurius-js/mercurius/pull/678 and shipped as v8.11.2. As a workaround users may use a custom error handler.","published":"2021-12-13T20:15:07.577Z","modified":"2026-07-09T12:20:00.517476Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mercurius","fixedVersion":"8.11.2"}],"fix":{"url":"https://github.com/mercurius-js/mercurius/pull/678/commits/732b2f895312da8deadd7b173dcd2d141d54b223","label":"mercurius-js/mercurius#678"},"references":[{"type":"FIX","url":"https://github.com/mercurius-js/mercurius/issues/677"},{"type":"FIX","url":"https://github.com/mercurius-js/mercurius/pull/678/commits/732b2f895312da8deadd7b173dcd2d141d54b223"},{"type":"FIX","url":"https://github.com/mercurius-js/mercurius/security/advisories/GHSA-273r-rm8g-7f3x"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:20:00.517476Z"}}