Avoiding GraphQL insecurities with OWASP SKF 🚀

Опубликовано: 08 Август 2026
на канале: OWASP HU
527
12

📖 GraphQL is quickly becoming the alternative to REST API, being able to request a specified set of data across multiple resources within a single request. But with great power comes great security risks. A single point of failure could allow attackers to create complex queries and exhaust resources (DoS), or bypass authorization to retrieve unauthorized information. This talk is a perfect match to boost your GraphQL skills, and learn how to exploit wrong implementations of the framework. Also next to that we will show that with the OWASP-SKF tool you can spot these possible vulnerabilities in an early stage by selecting the right security requirements for your development project and create the right awareness and guidance to prevent these mistakes.

⏱ Duration: 60' talk/workshop + QA + chatting
🇬🇧 Language: EN

👨🏼‍🤝‍👨🏻 Speakers
🇳🇱 Glenn ten Cate [NL/BE]:   / glenn-ten-cate  
🇮🇹 Davide Cioccia [IT/NL]:   / davidecioccia  

👓 Slides: https://www.slideshare.net/davidecioc...

Event announcement: https://www.meetup.com/OWASP-HU/event...

Timecodes:
00:00 - Intro by the chapter
00:07:00 -- Introduction of the speakers
00:09:50 -- Davide Cioccia, GraphQL insecurities
00:59:55 -- Glenn ten Cate, Managing insecurities with OWASP SKF
01:28:05 -- Q&A part