
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-104852 is a prototype pollution vulnerability in the mergeDeep utility function of the @graphql-tools/utils npm package (part of the GraphQL Tools project by ardatan). The flaw allows an unauthenticated remote attacker to corrupt the JavaScript prototype chain — specifically overwriting Function.prototype.call — by sending a single crafted GraphQL query, resulting in a permanent denial of service until the process is restarted. All versions of @graphql-tools/utils up to and including 12.0.0 are affected; version 12.0.1 contains the fix. The advisory was published on October 5, 2026, with a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory).
The root cause is CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). The mergeDeep function in @graphql-tools/utils iterated over source object keys using for...in, which traverses inherited properties, and checked for existing keys using the in operator rather than Object.prototype.hasOwnProperty. It also did not exclude reserved prototype-chain keys (__proto__, constructor, prototype). An attacker exploits this by aliasing GraphQL fields to these reserved names in a query against a supergraph that merges results from two subgraphs (e.g., @shareable or entity resolution). When the two subgraph responses are merged, the colliding keys cause mergeDeep to walk {}.constructor → Object → Object.__proto__ → Function.prototype, ultimately writing an attacker-controlled value over Function.prototype.call. The fix (PR #8423) adds an explicit guard to skip __proto__, constructor, and prototype keys at every recursion level and replaces the in check with hasOwnProperty (GitHub Advisory, Fix PR).
Successful exploitation causes a permanent denial of service: once Function.prototype.call is overwritten with a subgraph-supplied value, all subsequent JavaScript function calls in the Node.js process fail, rendering the supergraph gateway completely unable to process any further requests until the service is manually restarted. There is no confidentiality or integrity impact beyond the availability disruption — the vulnerability does not enable code execution, data exfiltration, or lateral movement. Any supergraph using @graphql-tools/utils ≤12.0.0 that merges objects from two or more subgraphs (the standard @shareable or entity federation pattern) is affected (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication and no user interaction, and is triggerable with a single malformed GraphQL query against any supergraph that performs standard object merging from two subgraphs — making it highly accessible to any network-reachable attacker. The EPSS score is 0.0 and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires the specific precondition that the target supergraph merges results from at least two subgraphs for the same field (e.g., via @shareable or entity resolution).
@graphql-tools/utils ≤12.0.0 that uses federated subgraph merging (e.g., @shareable fields or entity resolution across two subgraphs).constructor and nests a further alias to __proto__, with a leaf alias of call, targeting a shared field resolved by two subgraphs:{
shared {
fieldA
constructor: fieldB {
__proto__: child {
call: value
}
}
}
}mergeDeep processes the colliding constructor/__proto__/call keys, traverses the prototype chain from {} → Object → Function.prototype, and overwrites Function.prototype.call with the subgraph-supplied value.constructor, __proto__, or prototype in the query body; a single such request followed by the gateway becoming unresponsive to all subsequent requests.TypeError or is not a function errors in Node.js process logs immediately following the malicious request, indicating Function.prototype.call corruption.The primary remediation is to upgrade @graphql-tools/utils to version 12.0.1 or later, which skips __proto__, constructor, and prototype keys at every recursion level in mergeDeep and uses hasOwnProperty for existing-key checks (GitHub Advisory, Release). For Hive Gateway users, a gateway-level mitigation is available via PR #2600, which strips prototype-polluting keys from subgraph results before merging, even before the underlying library is updated (Hive Gateway PR). As an additional defense-in-depth measure, implement input validation or a GraphQL query firewall to reject queries containing field aliases matching __proto__, constructor, or prototype.
The fix was authored by contributor enisdenjo and reviewed and approved by project maintainer ardatan, with the patch merged on September 7, 2026 and the advisory published on October 5, 2026 (Fix PR, GitHub Advisory). The vulnerability was also noted on Bluesky via the CVE tracking account shortly after disclosure. No significant broader media coverage or threat actor commentary has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."