CVE-2026-103921

Published: Ott 01, 2026 Last Modified: Ott 01, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,4
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.

295

Improper Certificate Validation

Draft
Common Consequences
Security Scopes Affected:
Integrity Authentication
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Not Technology-Specific, Web Based, Mobile
View CWE Details
https://github.com/ardatan/graphql-tools/commit/3831a0661514c91d99971052f983552…
https://github.com/ardatan/graphql-tools/pull/8426
https://github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/executor-l…
https://github.com/ardatan/graphql-tools/security/advisories/GHSA-6fw5-9hq8-w87g