GraphQL

29 posts

The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability
GraphQL

The Paradox of Disabling GraphQL Introspection: Lessons from the Parse Server GraphQL API vulnerability

Last week, the security community was alerted to a vulnerability in Parse Server GraphQL API, which allowed public access to the GraphQL schema without requiring a session token or the master key. It is now identified as CVE-2025-53364. So, the question comes up: Should we disable introspection entirely in production
Antoine Carossio
Antoine Carossio
4 min read
The State of GraphQL Security 2024
API Security

The State of GraphQL Security 2024

Insights from 13,000 GraphQL API issues: Read our deep dive into the current state of GraphQL security.
Alexandra Charikova
Alexandra Charikova
2 min read
How to secure GraphQL APIs: challenges and best practices
GraphQL Security

How to secure GraphQL APIs: challenges and best practices

GraphQL APIs, while offering robust features and flexibility, present unique security challenges compared to traditional REST APIs. This article delves into the complexities of securing GraphQL APIs, highlighting common vulnerabilities and providing a comprehensive guide to best practices for building secure GraphQL apps. A visual learner? Check out our latest
Alexandra Charikova
Alexandra Charikova
6 min read
[Webinar] How to secure GraphQL
API Security

[Webinar] How to secure GraphQL

Join Uri Goldshtein and Tristan Kalos for a webinar on GraphQL security and learn to secure your GraphQL APIs.
Tristan Kalos
Tristan Kalos
1 min read
API Catalog & API Portal: A handbook of everything you should know
API

API Catalog & API Portal: A handbook of everything you should know

Discover the importance of API catalogs, their differences from API portals & gateways, and how to ensure optimal API management and security.
Nohé Hinniger-Foray
Nohé Hinniger-Foray
9 min read
How we found a security misconfiguration in Philips' GraphQL API
Announcement

How we found a security misconfiguration in Philips' GraphQL API

It is a misconception that discovering vulnerabilities is only within the domain of developers and hackers. Jacob, an Account Executive at Escape, proves this notion wrong. What is a vulnerability disclosure? Vulnerability disclosure is the process of reporting security weaknesses in computer software or hardware. Individuals and groups such as
Escape - Offensive Security
Escape - Offensive Security
3 min read
Escape and Xolvio officially partner to help teams secure their GraphQL APIs!
Announcement

Escape and Xolvio officially partner to help teams secure their GraphQL APIs!

Keeping APIs secure is vital. However, not all organizations have the in-house resources to tackle it effectively. Xolvio's clients can now leverage Escape's expertise in GraphQL security and performance assessments. They can also integrate it into their CI/CD pipelines, enhancing their API security
Alexandra Charikova
Alexandra Charikova
2 min read
What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them
GraphQL

What are Insecure Direct Object References (IDOR) in GraphQL, and how to fix them

As developers, ensuring the security of our applications is crucial. Insecure Direct Object References (IDOR) are common security vulnerabilities that occur when a system's internal implementation is exposed to users, allowing them to manipulate references to access unauthorized data. GraphQL, a powerful data query and manipulation language for
Tristan Kalos
Tristan Kalos
8 min read
API Security Academy: How It Works Under the Hood
API Security

API Security Academy: How It Works Under the Hood

The API Security Academy is built upon a technology that comes straight from the future—and by that, we mean the brilliant minds at StackBlitz - WebContainers. You may already know regular containers, the ones you can run with Docker and Kubernetes, which are lightweight virtualization units that allow developers
Gautier Ben Aïm
Gautier Ben Aïm
3 min read
API Security Academy: a smarter way to learn GraphQL security
GraphQL

API Security Academy: a smarter way to learn GraphQL security

Learning about GraphQL security is now more accessible than ever! We're excited to introduce the API Security Academy, developed by the Escape team. Escape's API Security Academy is a free and open-source collection of interactive challenges that will teach you how to secure your GraphQL applications.
Gautier Ben Aïm
Gautier Ben Aïm
3 min read
GraphQL Security: Challenges & Best Practices for DApps
Web3 Security

GraphQL Security: Challenges & Best Practices for DApps

Apart from the issue of poor user experience, security is one of the greatest setbacks to global Web3. Blackhats are constantly exploiting Web3 applications to siphon funds. On the 2nd of July, 2023, Poly Network lost about $5 million to a hack. Atomic Wallet lost over $100 million to a
Escape - Offensive Security
Escape - Offensive Security
6 min read
GraphQL Wordlist: Free Open Source for Penetration Testing
GraphQL

GraphQL Wordlist: Free Open Source for Penetration Testing

In cybersecurity, the old saying that the "best defense is a good offense" rings true. This philosophy is reflected in the approach we call offensive security. It involves actively seeking out system vulnerabilities to fix them before they can be exploited. It's about taking the initiative,
Nohé Hinniger-Foray
Nohé Hinniger-Foray
5 min read
Goctopus: Open Source GraphQL Discovery & Fingerprinting
GraphQL

Goctopus: Open Source GraphQL Discovery & Fingerprinting

In the fast-evolving domain of APIs, GraphQL has emerged as a powerful, data-oriented language. As its adoption soars, so does the need for robust tools to discover and fingerprint these APIs. Enter Goctopus, a Golang-based solution we developed at Escape to provide comprehensive, fast, and interoperable endpoint discovery and fingerprinting
Nohé Hinniger-Foray
Nohé Hinniger-Foray
7 min read
Escape raises $3.9 million in seed to secure APIs at every development stage
Announcement

Escape raises $3.9 million in seed to secure APIs at every development stage

Official Press release * Six months after releasing its API security platform, Escape has already secured the applications of 1000+ organizations worldwide and just graduated from Y Combinator. * The funding will allow the company to hire new team members covering European and US-based customers, aiming to double the team’s size
Escape - Offensive Security
Escape - Offensive Security
4 min read
Unveiling the GraphQL API Catalog
Attack Surface Management

Unveiling the GraphQL API Catalog

Escape launches the first Asset Inventory and Attack Surface Management solution for GraphQL APIs with its new API Catalog feature.
Antoine Carossio
Antoine Carossio
3 min read
Introducing Seamless GraphQL Compliance
GraphQL

Introducing Seamless GraphQL Compliance

As your go-to partner in GraphQL Security, we at Escape are constantly innovating to simplify and streamline security for you. We're proud of our reputation for crafting modern, dynamic application security testing (DAST) tools tailored to GraphQL, beloved by developers and trusted by security teams worldwide. From comprehensive
Antoine Carossio
Antoine Carossio
3 min read
GraphQL XSS: Cross-Site Scripting Explained
GraphQL Vulnerability

GraphQL XSS: Cross-Site Scripting Explained

Every Monday morning, you go through your ritual and check the users' feedback. This week, despite all the wonderful feedback, some users are complaining that someone has impersonated them and performed actions on their accounts without their knowledge. After some investigation, you discover that all the complaining users have
Achraf Ait Sidi Hammou
Achraf Ait Sidi Hammou
5 min read
GraphQL Input Validation & Sanitization
GraphQL

GraphQL Input Validation & Sanitization

Why input validation and sanitization are important in GraphQL? GraphQL allows you to identify the data and validate inputs based on type information. By default, GraphQL Specification has the Int, Float, String, Boolean and ID Scalar types. But as a conscious API developer, you've probably come across situations
Antoine Carossio
Antoine Carossio
5 min read
Top 5 GraphQL vulnerabilities burdening HIPAA compliance
GraphQL

Top 5 GraphQL vulnerabilities burdening HIPAA compliance

TL;DR: GraphQL vulnerabilities will inevitably burden organizations, especially when healthcare compliances like HIPAA come into play. This article highlights how Escape makes it super easy to release compliant APIs. The correlation between HIPAA and GraphQL is that PHI resources can be exposed through GraphQL APIs, allowing for a more
Escape - Offensive Security
Escape - Offensive Security
5 min read
Find & Fix GraphQL API Security Issues with Postman
Postman

Find & Fix GraphQL API Security Issues with Postman

Improve the security of your GraphQL API with Escape and Postman Are you tired of dealing with pesky API vulnerabilities? Want to take your GraphQL game to the next level? Introducing the perfect combo for GraphQL success - Escape and Postman. Escape is a tool that helps developers automatically and
Nohé Hinniger-Foray
Nohé Hinniger-Foray
3 min read
GraphQL Performance: How to Test & Optimize
GraphQL

GraphQL Performance: How to Test & Optimize

Quickly identify potential DoS, Complexity, N+1 issues, and more.
Sophie Boulaaouli
Sophie Boulaaouli
4 min read
GraphQL Pentesting: Thinking Outside the Box
Pentesting

GraphQL Pentesting: Thinking Outside the Box

The hardest part when pentesting any system is undoubtedly answering the question: 💡How should we think of that? What is meant is "how outside-the-box thinking works?", and "how is a pentester meant to think outside the box?". Although tackling this question might seem like a near
Karim Rustom
Karim Rustom
3 min read
How to Secure GraphQL APIs in CI/CD: Best Practice
GraphQL

How to Secure GraphQL APIs in CI/CD: Best Practice

Secure your GraphQL APIs in CI/CD with Escape DAST that supports GraphQL natively.
Karim Rustom
Karim Rustom
4 min read
GraphQL Security: How to Prevent Data Breaches
GraphQL

GraphQL Security: How to Prevent Data Breaches

Manage your sensitive data in GraphQL applications (PII, passwords, secrets…) We released a new feature in Escape that enables you to detect and fix data leaks with GraphQL. 🚫 The GraphQL Access Control issue, what is it? Access control is the restriction that tells the user who or what can be
Sophie Boulaaouli
Sophie Boulaaouli
3 min read