CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws
Vulnerability ID: CVE-2026-103921
CVSS Score: 7.4
Published: 2026-10-05
A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.
TL;DR
The @graphql-tools/executor-legacy-ws package failed to validate TLS certificates for outgoing wss:// connections, leaving Node.js applications vulnerable to credential theft and message manipulation via Adversary-in-the-Middle (MitM) attacks.
Technical Details
- CWE ID: CWE-295 (Improper Certificate Validation)
- Attack Vector: Network (Requires MitM positioning)
- CVSS v3.1 Score: 7.4 (High Severity)
- EPSS Score: 0.00268 (Percentile: 17.20%)
- Exploit Status: No public functional exploit payload available
- CISA KEV Status: Not listed
- Ransomware Association: No known usage
Affected Systems
- Node.js server applications implementing legacy GraphQL WebSocket subscriptions
- GraphQL backend microservices utilizing @graphql-tools/url-loader
- Server-side Javascript environments with outdated graphql-tools dependencies
-
@graphql-tools/executor-legacy-ws: < 1.1.35 (Fixed in:
1.1.35) -
@graphql-tools/url-loader: < 9.1.8 (Fixed in:
9.1.8)
Code Analysis
Commit: 3831a06
Enable TLS certificate validation by default for legacy GraphQL WebSocket connections over wss://.
@@ -37,7 +43,7 @@ export function buildWSLegacyExecutor(
websocket = new WebSocketImpl(subscriptionsEndpoint, 'graphql-ws', {
followRedirects: true,
headers: options?.headers,
- rejectUnauthorized: false,
+ rejectUnauthorized: options?.rejectUnauthorized ?? true,
skipUTF8Validation: true,
});
Mitigation Strategies
- Upgrade @graphql-tools/executor-legacy-ws to version 1.1.35 or higher.
- Upgrade transitive dependency @graphql-tools/url-loader to version 9.1.8 or higher.
- Ensure rejectUnauthorized is not set to false in any production-facing configurations.
- Isolate internal testing environments that require self-signed certificates from production pipelines.
Remediation Steps:
- Identify all Node.js projects utilizing @graphql-tools/executor-legacy-ws or @graphql-tools/url-loader.
- Run 'npm install @graphql-tools/executor-legacy-ws@1.1.35' or update the package lockfile to ensure version alignment.
- Audit application instantiation files for explicit rejectUnauthorized overrides.
- Deploy the updated codebase and verify that connection attempts to invalid endpoints now throw TLS connection failures.
References
- GitHub Security Advisory GHSA-6fw5-9hq8-w87g
- Fix Commit 3831a0661514c91d99971052f983552556880402
- @graphql-tools/executor-legacy-ws Release 1.1.35
- NVD CVE-2026-103921 Detail
- CVE.org CVE-2026-103921 Record
Read the full report for CVE-2026-103921 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)