CVE-2026-107376 | webonyx graphql-php up to 15.32.2 Parser parseSelectionSet recursion

SecurityVulns

A vulnerability identified as critical has been detected in webonyx graphql-php up to 15.32.2. This impacts the function parseSelectionSet of the component Parser. This manipulation causes uncontrolled recursion.

This vulnerability is handled as CVE-2026-107376. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More