Vulnerability DatabaseRUSTSEC-2022-0037

RUSTSEC-2022-0037
Rust vulnerability analysis and mitigation

Overview

The vulnerability RUSTSEC-2022-0037 affects the async-graphql library, where a potential denial of service could occur due to unbounded recursion in GraphQL queries. The issue was discovered and addressed in 2022, impacting applications using the async-graphql crate (GitHub Commit).

Technical details

The vulnerability stems from the lack of recursive depth limitation in GraphQL query processing. Prior to the fix, the library did not implement any restrictions on query depth, which could lead to stack overflow conditions. The fix implemented a default maximum recursive depth of 256 levels for GraphQL queries, with the ability to configure this limit through the limit_recursive_depth function (GitHub Commit).

Impact

If exploited, this vulnerability could allow attackers to craft deeply nested GraphQL queries that could potentially cause stack overflow conditions, leading to denial of service of the affected application (GitHub Commit).

Mitigation and workarounds

The issue has been fixed by implementing a default recursive depth limit of 256 levels. Applications using async-graphql should upgrade to the patched version. Additionally, developers can customize the recursive depth limit using the limit_recursive_depth function to set an appropriate value for their specific use case (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-qqc3-94qv-7fw3MEDIUM6.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026
GHSA-f45q-w629-wr25MEDIUM6.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026
GHSA-g9hv-x236-4qp3MEDIUM5.3
  • Rust logoRust
  • russh
NoYesJul 24, 2026
GHSA-cqjc-rmpq-xprqMEDIUM4.3
  • Rust logoRust
  • russh
NoYesJul 24, 2026
GHSA-2625-rw7m-5q5xLOW2.3
  • Rust logoRust
  • hubuum_client
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management