Vulnerability DatabaseCVE-2026-104852

CVE-2026-104852: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-104852 is a prototype pollution vulnerability in the mergeDeep utility function of the @graphql-tools/utils npm package (part of the GraphQL Tools project by ardatan). The flaw allows an unauthenticated remote attacker to corrupt the JavaScript prototype chain — specifically overwriting Function.prototype.call — by sending a single crafted GraphQL query, resulting in a permanent denial of service until the process is restarted. All versions of @graphql-tools/utils up to and including 12.0.0 are affected; version 12.0.1 contains the fix. The advisory was published on October 5, 2026, with a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory).

Technical details

The root cause is CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — Prototype Pollution). The mergeDeep function in @graphql-tools/utils iterated over source object keys using for...in, which traverses inherited properties, and checked for existing keys using the in operator rather than Object.prototype.hasOwnProperty. It also did not exclude reserved prototype-chain keys (__proto__, constructor, prototype). An attacker exploits this by aliasing GraphQL fields to these reserved names in a query against a supergraph that merges results from two subgraphs (e.g., @shareable or entity resolution). When the two subgraph responses are merged, the colliding keys cause mergeDeep to walk {}.constructor → Object → Object.__proto__ → Function.prototype, ultimately writing an attacker-controlled value over Function.prototype.call. The fix (PR #8423) adds an explicit guard to skip __proto__, constructor, and prototype keys at every recursion level and replaces the in check with hasOwnProperty (GitHub Advisory, Fix PR).

Impact

Successful exploitation causes a permanent denial of service: once Function.prototype.call is overwritten with a subgraph-supplied value, all subsequent JavaScript function calls in the Node.js process fail, rendering the supergraph gateway completely unable to process any further requests until the service is manually restarted. There is no confidentiality or integrity impact beyond the availability disruption — the vulnerability does not enable code execution, data exfiltration, or lateral movement. Any supergraph using @graphql-tools/utils ≤12.0.0 that merges objects from two or more subgraphs (the standard @shareable or entity federation pattern) is affected (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability requires no authentication and no user interaction, and is triggerable with a single malformed GraphQL query against any supergraph that performs standard object merging from two subgraphs — making it highly accessible to any network-reachable attacker. The EPSS score is 0.0 and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack requires the specific precondition that the target supergraph merges results from at least two subgraphs for the same field (e.g., via @shareable or entity resolution).

Exploitation steps

  1. Reconnaissance: Identify a publicly accessible GraphQL supergraph endpoint running @graphql-tools/utils ≤12.0.0 that uses federated subgraph merging (e.g., @shareable fields or entity resolution across two subgraphs).
  2. Craft the malicious query: Construct a GraphQL query that aliases a field to constructor and nests a further alias to __proto__, with a leaf alias of call, targeting a shared field resolved by two subgraphs:
{
  shared {
    fieldA
    constructor: fieldB {
      __proto__: child {
        call: value
      }
    }
  }
}
  1. Send the query: Submit the crafted query via HTTP POST to the supergraph endpoint (no authentication required).
  2. Trigger prototype pollution: When the gateway merges the two subgraph responses, mergeDeep processes the colliding constructor/__proto__/call keys, traverses the prototype chain from {} → Object → Function.prototype, and overwrites Function.prototype.call with the subgraph-supplied value.
  3. Achieve denial of service: All subsequent JavaScript function invocations in the gateway process fail, causing the service to become unresponsive to all further requests until a manual restart is performed (GitHub Advisory, Fix PR).

Indicators of compromise

  • Network: Incoming GraphQL POST requests containing field aliases matching constructor, __proto__, or prototype in the query body; a single such request followed by the gateway becoming unresponsive to all subsequent requests.
  • Logs: Application/gateway logs showing a sudden cessation of successful request processing after a specific GraphQL query; JavaScript TypeError or is not a function errors in Node.js process logs immediately following the malicious request, indicating Function.prototype.call corruption.
  • Process: The Node.js gateway process remains running but stops responding to all GraphQL queries; health check endpoints begin failing; manual process restart restores service.

Mitigation and workarounds

The primary remediation is to upgrade @graphql-tools/utils to version 12.0.1 or later, which skips __proto__, constructor, and prototype keys at every recursion level in mergeDeep and uses hasOwnProperty for existing-key checks (GitHub Advisory, Release). For Hive Gateway users, a gateway-level mitigation is available via PR #2600, which strips prototype-polluting keys from subgraph results before merging, even before the underlying library is updated (Hive Gateway PR). As an additional defense-in-depth measure, implement input validation or a GraphQL query firewall to reject queries containing field aliases matching __proto__, constructor, or prototype.

Community reactions

The fix was authored by contributor enisdenjo and reviewed and approved by project maintainer ardatan, with the patch merged on September 7, 2026 and the advisory published on October 5, 2026 (Fix PR, GitHub Advisory). The vulnerability was also noted on Bluesky via the CVE tracking account shortly after disclosure. No significant broader media coverage or threat actor commentary has been identified at this time.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management