Skip to content

standard

GraphQL

GraphQL is a query language and runtime for APIs, letting clients request exactly the data they need from nested, relational schemas.

Known aliases

  • /api/graphql

Relationships

No evidence-backed relationships are recorded.

Current stories

security7 publishers

GitLab's 9.4 GraphQL bug went from patch to in-the-wild traffic in about two days

WatchTowr reproduced CVE-2026-19478 from the advisory and patch alone, then caught the first exploitation attempts on its honeypots. Self-managed owners do not get a week to schedule this.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 62%
Investor
Investor 9%

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence70
security7 publishers

Fully patched Magento stores are being backdoored four days ahead of Adobe's next security release

Sansec reproduced an unauthenticated code-execution chain on clean 2.4.7, 2.4.8 and 2.4.9 installs, and the first victim it saw was already on Adobe's newest patch level for its release line.

Perspective Coverage

7 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence78
Adoption55
Hype gap+15
Incentives55
Confidence75
build1 publisher

ServiceNow's three CVSS 10.0 flaws run with the privileges of the platform itself

The writeup lists three conditions that all have to hold for exploitation, and an instance that answers on the public internet already satisfies the first, leaving only the hotfix and the WAF rules standing between exposure and exploit -- which is why this is a same-day hotfix, not a sprint ticket.

Publishers:dev.to

Reality

Evidence44
Adoption
Insufficient
Hype gap+12
Incentives35
Confidence38