The Application Security Podcast cover image

Nick Aleks and Dolev Farhi -- GraphQL Security

The Application Security Podcast

00:00

Do You Have a Zero Day in the GraphQL Spec?

There is a concept called directives in GraphQL and directives can be applied to schema, so on the server side, but they can also be provided by the client. There's no limit on the amount of directive that you can send on the same type of field. So we realized that when you pass many, many, many,. like, thousands of those, like, at symbol, let's take network as an example. And there's no mention of security around it, how to protect against it. It's really tricky to actually protect against that as well.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app