Impact
GraphQL Tools’ legacy WebSocket executor disables TLS certificate validation by default, allowing an attacker in a position to intercept the network traffic to accept a forged or self‑signed certificate. This deficiency lets the attacker acquire authentication material that is transmitted in connection parameters or headers and modify or spoof subscription data. The vulnerability is a classic example of improper SSL/TLS validation (CWE‑295).
Affected Systems
Systems using the @graphql-tools:executor‑legacy‑ws or ardatan:graphql‑tools packages in any version older than 1.1.35 are affected. The issue manifests when an application invokes the executor‑legacy‑ws helper directly, or when a URL loader with SubscriptionProtocol.LEGACY_WS is used. Browser clients are unaffected because modern browsers enforce TLS validation on WebSocket connections.
Risk and Exploitability
The CVSS score is 7.4, indicating a high‑severity vulnerability. The EPSS score is not available, but the lack of introduction in the CISA KEV catalog suggests the flaw has not yet been widely exploited. The attack vector is a network‑positioned attacker capable of impersonating a trusted endpoint; the vulnerability allows remote interception of encrypted traffic, revealing credentials and enabling tampering of subscription payloads.
OpenCVE Enrichment