chiprook
← Security
SecurityOctober 6, 2026, 06:30

CVE-2026-103921: TLS certificate validation bypass in @graphql-tools/executor-legacy-ws

@graphql-tools/executor-legacy-ws before 1.1.35 hardcodes rejectUnauthorized: false for outgoing wss:// connections, letting MitM attackers capture or tamper with GraphQL subscription data. The CWE-295 flaw is rated CVSS 7.4 and is fixed in executor-legacy-ws 1.1.35 and url-loader 9.1.8.

CVE-2026-103921: TLS certificate validation bypass in @graphql-tools/executor-legacy-ws
#GraphQL
Read next
Security

CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

Security

Cloudflare Plans Public Certificate Authority for Quantum-Safe TLS Certificates

Security

CERT Polska links 17 Android apps via a reused TLS certificate

Software

Android 17 adds Certificate Transparency checks for TLS certificates