A Comprehensive Study of Graph QL Security Challenges

Viloki Patel, Meet Chaudhary, Parth S. Patel, Jitendra B Upadhyay · International Research Journal on Advanced Engineering and Management (IRJAEM) · 2025

GraphQL is a highly flexible query language utilized for flexible API construction. It offers excellent benefits over conventional APIs because of its flexible nature and strong queries. It provides numerous benefits, but because of its dynamic nature and absence of built-in mechanisms, it is vulnerable to very critical attacks like injection attacks, denial of service (DoS) attacks, broken authentication and authorization, request forgery, schema introspection, and bad exception handling. By studying in detail, this paper discloses how the GraphQL APIs can be attacked by an attacker using a variety of attacks. The paper explains real-world attack methods with diagrams and examples, such as how to detect GraphQL, overloading the server with complex queries, injecting the malicious code, brute-forcing credentials, and forging requests on the client and server sides.

Read the paper · More papers on PaperTik