Executive brief
GraphQL Armor is a security plugin that restricts GraphQL query complexity via cost-limiting to prevent denial-of-service attacks. When the introspection-ignore feature is enabled (the default), attackers can bypass cost limits by naming queries or fragments "__schema", allowing them to send expensive queries that exhaust server resources.
Technical details
The vulnerability is a logic error in the cost-limit plugin's introspection-bypass check. The computeComplexity function attempts to skip cost calculation for introspection queries by checking if a node's name equals "__schema", but fails to validate the node type. Since nodes can be FieldNode, FragmentDefinitionNode, OperationDefinitionNode, or others, attackers can bypass the check by naming a query or fragment "__schema" instead of using the "__schema" field, causing cost calculation to be skipped entirely. The fix restricts the check to FieldNode types only. No authentication is required; the vulnerability is exploitable by any unauthenticated network client sending a crafted GraphQL query. Fixed in version 2.4.2.
Affected products
- Escape Technologies graphql-armor-cost-limit <= 2.4.0
Timeline
- 2025-04-25: disclosed
- 2025-04-25: patched: Fixed in version 2.4.2