GraphQL—Time for Some Introspection

Devam Shah, Devansh Shah, Pratidnya Hegdepatil, Aaryen Toggi · 2024

GraphQL has been here since 2015 (public), but only recently there has been a surge in its usage by developers. Although GraphQL security is becoming crucial given the increasing usage, there are only a few research papers that particularly cover this topic. To close this gap, this review paper compiles data from multiple web sources to offer a summary of security considerations, flaws, and best practices related to GraphQL. We look at common security risks like injection attacks, unauthorized access, and denial of service attacks. We also look at mitigation techniques and countermeasures. It is the goal of this review to provide a basic resource for researchers, practitioners, and developers interested in comprehending and improving the security of GraphQL-based applications.

Read the paper · More papers on PaperTik