Skip to main content
GraphQL

GraphQL

Programming languageWikipedia

Search complete. 104 mentions across 47 episodes found for "GraphQL".

Sep 12, 2026

speaker_0HOST
4:34
My notes show GitLab also just patched two other critical flaws.
speaker_0HOST
4:38
There's a GraphQL code injection flaw, CVE-2026-99478.
speaker_0HOST
4:40
Right.
speaker_0HOST
4:40
And the other is CVE-2026-8771-TIME.
speaker_1HOST
4:46
Which is a CDSS 9.9, by the way.
speaker_0HOST
4:49
Right, 9.9. And that one is described as an insecure deserialization bug in DuoChat access that bypasses serialization via crafted GraphQL subscription argument.
speaker_1HOST
4:57
That's a mouthful.
speaker_0HOST
4:58
It really is.
Rich StroffolinoHOST
10:06
Adobe says it's working on a fix, but hasn't offered a release time.
Rich StroffolinoHOST
10:09
Sansa recommends disabling GraphQL and rotating Magento credentials if a compromise is suspected.
Rich StroffolinoHOST
10:16
Um, you know, e-commerce zero day, uh, I can't think of a better way to kick off the weekend here.
Rich StroffolinoHOST
10:21
Mark, anything here to, uh, uh, that, uh, you wanna know more about within this story? A lot of interesting technical details here, or Sansa has the mitigations out, a patch will be out, dot, dot, dot, someday.
Hussein NasserHOST
7:22
So you see how precious these calls get.
Hussein NasserHOST
7:25
So back to our life, how we do things is when we execute... a REST call or a GraphQL or any endpoint or a SQL statement, we just assume that, you know what, I'm not going to do that again.
Hussein NasserHOST
7:41
That's slow.
Hussein NasserHOST
7:42
Let's just cache it.
Will CoryGUEST
15:07
I think for the most part, the default is exactly what you said, where I think we'll just collapse on the same standards we've been using all the time.
Will CoryGUEST
15:16
OpenAPI, GraphQL, Nix, all these things are definitely no reason to invent a new thing for the most part.
Will CoryGUEST
15:28
I think this is really interesting and something I thought a lot about as just someone who's building tools, right? It's like what actually does, like what does something that actually does deserve to be built new look like, right? And I think what that looks like is when kind of the fundamental math you do of like how should this abstraction look and what should it optimize for, whenever that changes based on agents, like fundamentally what you want.
Will CoryGUEST
15:54
So like I think a really good example of this actually is just, the way we do pull requests, for example, the way we like get code merged, right? I think a lot of people will report, like if you start having like these like high velocity, many agents working at once, when it comes to this, I think you'll notice that like your agents just get stuck In rebase hell, they get just stuck having to...
Brian DouglasHOST
21:19
And it's telling its own stories, but to all the influence.
Brian DouglasHOST
21:22
And I wonder...
Brian DouglasHOST
21:24
We don't need another GraphQL.
Brian DouglasHOST
21:25
We'd rather do another OpenAPI spec.
Paul BakkerGUEST
4:35
Yeah, probably.
Paul BakkerGUEST
4:37
Maybe we have to deal with it and talk too much about GraphQL because I think we were integrating with Spring for GraphQL at the time.
Josh LongHOST
4:45
Yeah.
Paul BakkerGUEST
4:45
It seems many years ago now.
Paul BakkerGUEST
5:41
Been a bunch of different teams, worked on a bunch of different things, but for the last four or five years or so, I've been in what we call the Java platform team.
Paul BakkerGUEST
5:49
So my team is responsible for Spring Boot, for example, and making that available to all developers.
Paul BakkerGUEST
5:55
I've worked a lot on our GraphQL stack in the past and a framework that we built for that.
Paul BakkerGUEST
5:59
And yeah, kind of all things Java, I tend to touch.
Kurt KempleGUEST
58:03
I rebuilt their mobile app.
Kurt KempleGUEST
58:04
Like I moved them to a technology called GraphQL, which allowed them to like get rid of a bunch of other stuff that was like overly complex and getting in the way.
Kurt KempleGUEST
58:13
It was very cool.
Kurt KempleGUEST
58:14
It was a fun job.
Kurt KempleGUEST
58:15
But that's where I wrote it.
Kurt KempleGUEST
58:17
And you know why I wrote it? Because I met so many people, a much bigger company, and two things had happened.
Kurt KempleGUEST
58:23
I had started to build up an actual presence in the community because I was writing about and talking about these technologies like GraphQL and React Native, which were emerging at the time, right? And then I also had enough job security at that point.
Kurt KempleGUEST
58:38
I had worked like seven or eight different jobs in tech.
Sarah DrasnerGUEST
1:50
That's the MCP for WebMCP, it's W3C like other standards bodies.
Sarah DrasnerGUEST
1:56
For WebMCP, you are really only working on it on the client, but that doesn't mean that it can't negotiate or create server actions like kickoff arrest or GraphQL API interaction.
Sarah DrasnerGUEST
2:10
Also, the way that people are using it agentically, you do have headless scenarios that you can use WebMCP.
Sarah DrasnerGUEST
2:16
But we're also thinking about a new surface area of co-browse.

9 MINS LATER

Sarah DrasnerGUEST
11:27
So don't leverage the existing DOM structure.
Sarah DrasnerGUEST
11:30
Think in agent actions.
Sarah DrasnerGUEST
11:33
I would also want to leverage existing APIs in your application like REST or GraphQL.
Sarah DrasnerGUEST
11:39
If you have those, those can be invoked with a tool with a really good description.
Sarah LaneHOST
5:10
Adobe says it's working on a fix but hasn't offered a release time.
Sarah LaneHOST
5:15
Sansec recommends disabling GraphQL and rotating Magento credentials if compromise is suspected.
Sarah LaneHOST
5:23
[transition effect] Shadow AI steps into the light.
Sarah LaneHOST
5:28
The UK's National Cybersecurity Centre says unapproved AI tools are creating security gaps companies may not see.
Sarah LaneSOUNDBITE_SPEAKER
43:42
Adobe says it's working on a fix, but hasn't offered a release time.
Sarah LaneSOUNDBITE_SPEAKER
43:47
Sansa recommends disabling GraphQL and rotating Magento credentials if compromise is suspected.
Gerald AugerHOST
43:57
Okay.
Gerald AugerHOST
44:00
I guess Magento...
Gerald AugerHOST
47:19
The patches are not available yet.
Gerald AugerHOST
47:22
They should be available September 8th, which is today, so I guess today you can patch it.
Gerald AugerHOST
47:28
Uh, but they say if you can't do it right away, disable GraphQL.
Gerald AugerHOST
47:32
Uh, I would strongly encourage you to figure out what disabling GraphQL does before you turn it off.
James AzarHOST
4:33
Because there is no patch, your mitigation options are limited, however very important.
James AzarHOST
4:39
SANSEC does recommend disabling GraphQL as an interim measure since the attack chain runs through that interface.
James AzarHOST
4:47
Monitor aggressively for unexpected K-worker or FC cache processes, suspicious crone entries, and any unusual temporary files in server directories.
James AzarHOST
4:59
And if you see any unexpected surges of payment transaction failed reminder emails, treat that as a potential exploitation indicator and investigate immediately.

37 more episodes mention GraphQL.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.