PT-2026-103947 · Npm · Graphql-Tools

·

CVE-2026-103921

·

Published

2026-10-01

·

Updated

2026-10-05

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GraphQL Tools versions prior to 1.1.35
Description The buildWSLegacyExecutor() function in the executor-legacy-ws module hardcodes the TLS certificate rejection to off for Node.js connections to wss:// endpoints. This allows applications using the executor directly, or the url-loader with SubscriptionProtocol.LEGACY WS, to accept certificates controlled by an attacker during a network interception. This can lead to the disclosure of authentication material within connectionParams or headers, and the modification of subscription data. Browser WebSocket clients are not affected as they enforce certificate validation.
Recommendations Update to version 1.1.35.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103921
GHSA-6FW5-9HQ8-W87G

Affected Products

Graphql-Tools