{"id":"CVE-2024-40094","aliases":["GHSA-h9mq-f6q5-6c8m"],"url":"https://o3.security/vulnerability/CVE-2024-40094","summary":"GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service","details":"GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.","published":"2024-07-30T00:00:00Z","modified":"2026-08-07T08:12:21.365449600Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"com.graphql-java:graphql-java","fixedVersion":"19.11"},{"ecosystem":"Maven","name":"com.graphql-java:graphql-java","fixedVersion":"20.9"},{"ecosystem":"Maven","name":"com.graphql-java:graphql-java","fixedVersion":"21.5"}],"fix":{"url":"https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a","label":"graphql-java/graphql-java@97743bc"},"references":[{"type":"WEB","url":"https://github.com/graphql-java/graphql-java/discussions/3641"},{"type":"WEB","url":"https://github.com/graphql-java/graphql-java/releases/tag/v19.11"},{"type":"WEB","url":"https://github.com/graphql-java/graphql-java/releases/tag/v20.9"},{"type":"WEB","url":"https://github.com/graphql-java/graphql-java/releases/tag/v21.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40094.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40094"},{"type":"FIX","url":"https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a"},{"type":"FIX","url":"https://github.com/graphql-java/graphql-java/pull/3539"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T08:12:21.365449600Z"}}