Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore GraphQL security vulnerabilities through this 32-minute conference talk that reveals hidden risks in GraphQL APIs. Learn how to identify and map security weaknesses including schema leaks, brute-force attack vectors, and GraphQL-specific "bomb" attacks that can compromise API security. Discover practical findings from real-world GraphQL API scanning and understand how the flexibility and efficiency of GraphQL can inadvertently create security blind spots. Gain insights into GraphQL-specific attack patterns and defensive strategies to protect against these emerging threats in modern API architectures.
Syllabus
BSidesSF 2025 - Decoding GraphQL: How to Map Hidden...(Antoine Carossio, Tristan Kalos)
Taught by
Security BSides San Francisco