CVE-2024-40094
MEDIUM
Published Jul 30, 2024
Modified Apr 15, 2026
Description
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.
Is your site exposed to CVE-2024-40094?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
5.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
References
Other References
https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a
https://github.com/graphql-java/graphql-java/discussions/3641
https://github.com/graphql-java/graphql-java/pull/3539
https://github.com/graphql-java/graphql-java/releases/tag/v19.11
https://github.com/graphql-java/graphql-java/releases/tag/v20.9
https://github.com/graphql-java/graphql-java/releases/tag/v21.5
https://github.com/graphql-java/graphql-java/commit/97743bc1b5caa2b0bd894dc8e128b47e4d771e4a
https://github.com/graphql-java/graphql-java/discussions/3641
https://github.com/graphql-java/graphql-java/pull/3539
https://github.com/graphql-java/graphql-java/releases/tag/v19.11
Frequently Asked Questions
What is CVE-2024-40094? +
GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions. It has a CVSS v3.1 base score of 5.3 (MEDIUM).
How severe is CVE-2024-40094? +
CVE-2024-40094 has a CVSS v3.1 score of 5.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
How do I check if I'm vulnerable to CVE-2024-40094? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.