Description
GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.
Published: 2026-10-01
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Compromise of authentication data and subscription integrity via TLS certificate validation bypass
Action: Immediate Patch
AI Analysis

Impact

GraphQL Tools’ legacy WebSocket executor disables TLS certificate validation by default, allowing an attacker in a position to intercept the network traffic to accept a forged or self‑signed certificate. This deficiency lets the attacker acquire authentication material that is transmitted in connection parameters or headers and modify or spoof subscription data. The vulnerability is a classic example of improper SSL/TLS validation (CWE‑295).

Affected Systems

Systems using the @graphql-tools:executor‑legacy‑ws or ardatan:graphql‑tools packages in any version older than 1.1.35 are affected. The issue manifests when an application invokes the executor‑legacy‑ws helper directly, or when a URL loader with SubscriptionProtocol.LEGACY_WS is used. Browser clients are unaffected because modern browsers enforce TLS validation on WebSocket connections.

Risk and Exploitability

The CVSS score is 7.4, indicating a high‑severity vulnerability. The EPSS score is not available, but the lack of introduction in the CISA KEV catalog suggests the flaw has not yet been widely exploited. The attack vector is a network‑positioned attacker capable of impersonating a trusted endpoint; the vulnerability allows remote interception of encrypted traffic, revealing credentials and enabling tampering of subscription payloads.

Generated by OpenCVE AI on October 1, 2026 at 17:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to GraphQL Tools version 1.1.35 or later to enable TLS certificate validation in the legacy WebSocket executor.
  • Review any custom code that calls executor‑legacy‑ws directly or uses SubscriptionProtocol.LEGACY_WS, and replace it with the updated executor or enforce manual certificate checks.
  • If an upgrade cannot be performed immediately, restrict outbound WebSocket connections to a trusted server set and enforce manual certificate validation on the client side or use a reverse proxy that performs certificate verification.

Generated by OpenCVE AI on October 1, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.
Title GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T16:32:37.865Z

Reserved: 2026-10-01T14:20:19.154Z

Link: CVE-2026-103921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:19.390

Modified: 2026-10-01T17:17:19.390

Link: CVE-2026-103921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T17:30:10Z

Weaknesses
  • CWE-295

    Improper Certificate Validation