CVE-2026-103921

🟡 Monitoruj

Błąd w GraphQL Tools umożliwia atakującemu przechwycenie danych przez akceptację nieautoryzowanych certyfikatów.

CVSS
7.4
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.4
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-01 17:17:19 UTC
Ostatnia modyfikacja (NVD)2026-10-02 18:44:45 UTC
Referencje