DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-103921: CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

Vulnerability ID: CVE-2026-103921
CVSS Score: 7.4
Published: 2026-10-05

A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.

TL;DR

The @graphql-tools/executor-legacy-ws package failed to validate TLS certificates for outgoing wss:// connections, leaving Node.js applications vulnerable to credential theft and message manipulation via Adversary-in-the-Middle (MitM) attacks.


Technical Details

  • CWE ID: CWE-295 (Improper Certificate Validation)
  • Attack Vector: Network (Requires MitM positioning)
  • CVSS v3.1 Score: 7.4 (High Severity)
  • EPSS Score: 0.00268 (Percentile: 17.20%)
  • Exploit Status: No public functional exploit payload available
  • CISA KEV Status: Not listed
  • Ransomware Association: No known usage

Affected Systems

  • Node.js server applications implementing legacy GraphQL WebSocket subscriptions
  • GraphQL backend microservices utilizing @graphql-tools/url-loader
  • Server-side Javascript environments with outdated graphql-tools dependencies
  • @graphql-tools/executor-legacy-ws: < 1.1.35 (Fixed in: 1.1.35)
  • @graphql-tools/url-loader: < 9.1.8 (Fixed in: 9.1.8)

Code Analysis

Commit: 3831a06

Enable TLS certificate validation by default for legacy GraphQL WebSocket connections over wss://.

@@ -37,7 +43,7 @@ export function buildWSLegacyExecutor(
       websocket = new WebSocketImpl(subscriptionsEndpoint, 'graphql-ws', {
         followRedirects: true,
         headers: options?.headers,
-        rejectUnauthorized: false,
+        rejectUnauthorized: options?.rejectUnauthorized ?? true,
         skipUTF8Validation: true,
       });
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade @graphql-tools/executor-legacy-ws to version 1.1.35 or higher.
  • Upgrade transitive dependency @graphql-tools/url-loader to version 9.1.8 or higher.
  • Ensure rejectUnauthorized is not set to false in any production-facing configurations.
  • Isolate internal testing environments that require self-signed certificates from production pipelines.

Remediation Steps:

  1. Identify all Node.js projects utilizing @graphql-tools/executor-legacy-ws or @graphql-tools/url-loader.
  2. Run 'npm install @graphql-tools/executor-legacy-ws@1.1.35' or update the package lockfile to ensure version alignment.
  3. Audit application instantiation files for explicit rejectUnauthorized overrides.
  4. Deploy the updated codebase and verify that connection attempts to invalid endpoints now throw TLS connection failures.

References


Read the full report for CVE-2026-103921 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)