GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.

Project Subscriptions

Vendors Products
Ardatan Subscribe
Executor-legacy-ws Subscribe
Graphql-tools Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Ardatan
Ardatan executor-legacy-ws
Ardatan graphql-tools
Vendors & Products Ardatan
Ardatan executor-legacy-ws
Ardatan graphql-tools

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.
Title GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T18:04:28.083Z

Reserved: 2026-10-01T14:20:19.154Z

Link: CVE-2026-103921

cve-icon Vulnrichment

Updated: 2026-10-01T18:04:19.347Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:19.390

Modified: 2026-10-01T19:17:18.647

Link: CVE-2026-103921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:33:42Z

Weaknesses