Skip to content

Add CVSS 3.1 severity for GHSA-cgqf-3cq5-wvcj#6873

Open
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6873from
sunnypatell:cvss-GHSA-cgqf-3cq5-wvcj
Open

Add CVSS 3.1 severity for GHSA-cgqf-3cq5-wvcj#6873
sunnypatell wants to merge 1 commit intogithub:sunnypatell/advisory-improvement-6873from
sunnypatell:cvss-GHSA-cgqf-3cq5-wvcj

Conversation

@sunnypatell
Copy link

Changes

Added CVSS 3.1 scoring to GHSA-cgqf-3cq5-wvcj (Apollo Router compressed payload limit bypass).

  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5 High)

CVSS justification

  • AV:N - exploitable over the network via GraphQL HTTP requests
  • AC:L/PR:N/UI:N - any unauthenticated client can send compressed payloads exceeding the configured HTTP limit
  • A:H - compressed payloads bypass size limits, allowing oversized requests that exhaust router memory and cause denial of service

References

Copilot AI review requested due to automatic review settings February 13, 2026 20:56
@github-actions github-actions bot changed the base branch from main to sunnypatell/advisory-improvement-6873 February 13, 2026 20:58
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds CVSS 3.1 severity scoring to the GitHub Security Advisory GHSA-cgqf-3cq5-wvcj for the Apollo Router compressed payload limit bypass vulnerability. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H assigns a score of 7.5 (High severity), reflecting a network-exploitable denial of service vulnerability that requires no authentication.

Changes:

  • Added CVSS 3.1 severity scoring to the security advisory
  • Populated the previously empty severity array with the appropriate vector string

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant