CYBER CODE RED

Get real-time updates on Telegram

Verified

GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`

CVE-2026-104852 affects @graphql-tools/utils. Affected range: <= 12.0.0. Fixed version: 12.0.1.

Published

CVE
CVE-2026-104852
CWE
CWE-1321
Product
@graphql-tools/utils
KEV
no

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-104852.html