Get real-time updates on Telegram
Verified
GraphQL Tools has prototype pollution in well-established utility function `mergeDeep`
CVE-2026-104852 affects @graphql-tools/utils. Affected range: <= 12.0.0. Fixed version: 12.0.1.
- CVE
- CVE-2026-104852
- CWE
- CWE-1321
- Product
- @graphql-tools/utils
- KEV
- no
Affected products
- @graphql-tools/utils · <= 12.0.0 · Fixed version: 12.0.1
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-05 23:24:49.857042+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104852.html