Vendor
An unauthenticated remote denial-of-service vulnerability in @graphql-tools/utils allows attackers to crash node processes via prototype pollution in the mergeDeep utility function.