CVE-2026-103921: TLS certificate validation bypass in @graphql-tools/executor-legacy-ws
@graphql-tools/executor-legacy-ws before 1.1.35 hardcodes rejectUnauthorized: false for outgoing wss:// connections, letting MitM attackers capture or tamper with GraphQL subscription data. The CWE-295 flaw is rated CVSS 7.4 and is fixed in executor-legacy-ws 1.1.35 and url-loader 9.1.8.
- CVSS 7.4 (High), CWE-295 improper certificate validation
- Affects executor-legacy-ws < 1.1.35 and url-loader < 9.1.8
- No public exploit payload; not listed in CISA KEV
- Fix sets rejectUnauthorized to true by default (commit 3831a06)
Read next
Security