
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-47713 is a denial-of-service (DoS) vulnerability in Hasura GraphQL Engine version 1.3.3 that allows unauthenticated remote attackers to crash the GraphQL endpoint by submitting malicious queries with excessively nested fields and extremely long query strings. The vulnerability was published on December 22, 2025, and is classified under CWE-770 (Allocation of Resources Without Limits or Throttling). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (VulnCheck Advisory, Feedly).
The root cause is CWE-770 — the Hasura GraphQL Engine 1.3.3 does not impose limits on query depth, complexity, or string length, allowing resource exhaustion through crafted inputs. An attacker can exploit this by sending HTTP POST requests containing deeply nested GraphQL field structures and extremely long query strings, optionally using multiple concurrent threads to amplify resource consumption. No authentication or special privileges are required, and no user interaction is needed, making this trivially exploitable over the network. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB PoC, VulnCheck Advisory).
Successful exploitation results in high availability impact — the GraphQL endpoint can be crashed or rendered unresponsive, denying service to legitimate users. There is no confidentiality or integrity impact associated with this vulnerability. Affected deployments relying on Hasura GraphQL Engine 1.3.3 as a data API layer may experience complete service outages, disrupting downstream applications and users (VulnCheck Advisory, Feedly).
A public proof-of-concept exploit is available on Exploit-DB (exploit ID 49789), and a VulnCheck advisory documents the attack technique. The EPSS score is approximately 0.038%, indicating a low but non-zero probability of exploitation in the wild. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Exploit-DB PoC, VulnCheck Advisory).
/v1/graphql).requests with concurrent.futures, or tools like wrk) to send the crafted query repeatedly across multiple threads simultaneously, amplifying resource consumption./v1/graphql from one or few source IPs; requests with abnormally large body sizes or extremely long query strings.The patch availability for Hasura GraphQL Engine 1.3.3 is currently unconfirmed; users should upgrade to the latest available version of Hasura GraphQL Engine and consult Hasura support for specific guidance (Hasura GitHub). As immediate workarounds, operators should implement GraphQL query depth and complexity limits at the API gateway or middleware layer, enforce rate limiting on the GraphQL endpoint, and validate/reject queries exceeding defined size thresholds. Temporarily restricting access to the GraphQL endpoint to trusted IP ranges and monitoring for anomalous query patterns are also recommended interim measures (VulnCheck Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."