CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-103921

CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

Alon Barad
Alon Barad
Software Engineer

Oct 5, 2026·6 min read·10 visits

Executive Summary (TL;DR)

The @graphql-tools/executor-legacy-ws package failed to validate TLS certificates for outgoing wss:// connections, leaving Node.js applications vulnerable to credential theft and message manipulation via Adversary-in-the-Middle (MitM) attacks.

A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.

Vulnerability Overview

The @graphql-tools/executor-legacy-ws package is a utility within the graphql-tools ecosystem designed to manage legacy WebSocket connection transports. Specifically, the buildWSLegacyExecutor() function sets up WebSocket endpoints using the older graphql-ws sub-protocol. When initiating a secure outbound WebSocket connection over wss:// within a Node.js runtime environment, the executor is responsible for establishing a cryptographically secure transport layer.

Prior to version 1.1.35, the package contained an architectural flaw where the TLS configuration parameter rejectUnauthorized was hardcoded to false. This parameter controls whether Node.js rejects connections from servers that present invalid, untrusted, or self-signed TLS certificates. Because this verification check was explicitly bypassed, the application failed to establish identity assurance for any remote WebSocket server.

This vulnerability is classified under CWE-295 (Improper Certificate Validation). The attack surface resides primarily in server-side JavaScript applications, backend microservices, or GraphQL gateways that communicate with remote GraphQL APIs over secure WebSockets. Clients executing within native web browsers are unaffected by this vulnerability, as web browsers ignore Node.js-specific WebSocket configurations and strictly enforce system-level certificate validation rules.

Technical Root Cause Analysis

The root cause of this vulnerability lies in the implementation of the buildWSLegacyExecutor function within packages/executors/legacy-ws/src/index.ts. When establishing a connection, the function instantiates a WebSocket client using a runtime-defined implementation, typically the ws package in Node.js. During this initialization, configuration parameters are passed to define transport-layer behaviors.

The codebase hardcoded the TLS options inside the constructor arguments. By setting rejectUnauthorized: false, the executor instructed the Node.js tls and https modules to bypass the validation of the peer certificate chain. This bypass disabled critical validation steps, including verifying that the certificate was signed by a trusted root Certificate Authority (CA), checking the expiration date of the certificate, and ensuring that the Common Name (CN) or Subject Alternative Name (SAN) of the certificate matched the destination hostname.

Consequently, the TLS socket failed open, accepting any X.509 certificate presented during the cryptographic handshake. An attacker capable of intercepting traffic at the network routing or DNS resolution layer could easily establish a TLS session using a self-signed or domain-mismatched certificate. The Node.js application would establish the WebSocket tunnel without throwing any warnings or connection errors, completely undermining the confidentiality and integrity assurances of the wss:// scheme.

Code Analysis and Patch Verification

An analysis of the fix implemented in Pull Request #8426 (commit 3831a0661514c91d99971052f983552556880402) demonstrates the transition to a secure-by-default posture. The vulnerable implementation in packages/executors/legacy-ws/src/index.ts had hardcoded options:

// Vulnerable Code
websocket = new WebSocketImpl(subscriptionsEndpoint, 'graphql-ws', {
  followRedirects: true,
  headers: options?.headers,
  rejectUnauthorized: false, // <-- Hardcoded bypass
  skipUTF8Validation: true,
});

The security patch introduced an explicit interface option rejectUnauthorized to both LegacyWSExecutorOpts and LoadFromUrlOptions. The default value is resolved using the nullish coalescing operator (?? true), ensuring that if the developer does not configure this option, it defaults securely to true:

// Patched Code
websocket = new WebSocketImpl(subscriptionsEndpoint, 'graphql-ws', {
  followRedirects: true,
  headers: options?.headers,
  rejectUnauthorized: options?.rejectUnauthorized ?? true, // <-- Secure default
  skipUTF8Validation: true,
});

This remediation ensures that Node.js validates the entire certificate chain against its list of trusted root authorities. The patch is cryptographically complete; it restores native validation rules by default while preserving functionality for developers who must explicitly disable validation when testing against local, self-signed mock environments.

Exploitation and Attack Methodology

To exploit this vulnerability, an attacker must position themselves on the network path between the vulnerable Node.js client application and the target GraphQL WebSocket server. This can be achieved through techniques such as local network ARP poisoning, DNS spoofing, or router compromising. The attacker does not need prior authentication to execute this attack.

Once positioned, the execution proceeds as follows:

During step 2, the attacker's gateway presents an arbitrary, self-signed certificate. Because of the vulnerability, the client skips certificate validation and establishes a secure-looking connection. During step 5, the client transmits subscription payloads, which routinely carry highly sensitive parameters inside HTTP headers or the connectionParams configuration object, such as authorization bearer tokens or user session identifiers. The attacker decrypts this outbound communication, extracts the secrets, and gains full access to downstream data feeds.

Security Impact Assessment

The security impact of CVE-2026-103921 is significant for enterprise backends that rely on real-time subscriptions. The CVSS base score of 7.4 reflects a high-severity threat. Since the attacker must establish an Adversary-in-the-Middle position, the Attack Complexity (AC) metric is rated as High. However, no privileges (PR:N) or user interactions (UI:N) are required to complete the exploitation.

Successful exploitation results in a complete loss of confidentiality and integrity for the affected WebSocket channel. Because WebSockets are designed for bidirectional, long-lived communications, attackers can not only harvest static credentials but also manipulate incoming message feeds. In systems tracking financial data, system events, or industrial monitoring, the injection of malicious data packets into the application flow could trigger secondary, critical logic failures.

The scope is limited to systems operating in server-side environments where JavaScript packages directly negotiate raw TLS streams. Desktop client applications developed with frameworks like Electron may also be affected if they employ these tools inside their background Node processes.

Remediation and Defensive Countermeasures

Remediation requires upgrading the underlying dependencies of the graphql-tools ecosystem. Developers should upgrade @graphql-tools/executor-legacy-ws to version 1.1.35 or higher. Applications that consume this executor transitively through @graphql-tools/url-loader must upgrade that package to version 9.1.8 or higher, which forces resolution of the patched executor.

In scenarios where third-party APIs use self-signed certificates in isolated, internal Virtual Private Clouds (VPCs), developers should avoid global environment overrides such as NODE_TLS_REJECT_UNAUTHORIZED=0, as this disables security globally. Instead, use the newly introduced rejectUnauthorized configuration property to surgically override validation checks only in local development environments.

Additionally, implementing active security monitoring at the network layer, such as deploying Intrusion Detection Systems (IDS) that flag unexpected TLS handshakes or unauthorized certificate changes, will help detect unauthorized MitM attempts.

Official Patches

Arda TanrikuluPull Request #8426 addressing legacy WS TLS issue

Fix Analysis (1)

Technical Appendix

CVSS Score
7.4/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Probability
0.27%
Top 83% most exploited

Affected Systems

Node.js server applications implementing legacy GraphQL WebSocket subscriptionsGraphQL backend microservices utilizing @graphql-tools/url-loaderServer-side Javascript environments with outdated graphql-tools dependencies

Affected Versions Detail

Product
Affected Versions
Fixed Version
@graphql-tools/executor-legacy-ws
Arda Tanrikulu
< 1.1.351.1.35
@graphql-tools/url-loader
Arda Tanrikulu
< 9.1.89.1.8
AttributeDetail
CWE IDCWE-295 (Improper Certificate Validation)
Attack VectorNetwork (Requires MitM positioning)
CVSS v3.1 Score7.4 (High Severity)
EPSS Score0.00268 (Percentile: 17.20%)
Exploit StatusNo public functional exploit payload available
CISA KEV StatusNot listed
Ransomware AssociationNo known usage

MITRE ATT&CK Mapping

T1557Adversary-in-the-Middle
Credential Access / Collection
CWE-295
Improper Certificate Validation

The application does not validate, or incorrectly validates, an association between an identity and a certificate, which can allow an attacker to spoof a trusted entity.

Vulnerability Timeline

Security patch merged into the master repository branch via PR #8426.
2026-09-08
Vulnerability publicly disclosed via GitHub Security Advisory and assigned CVE-2026-103921.
2026-10-01
NVD analysis updated.
2026-10-02

References & Sources

  • [1]GitHub Security Advisory GHSA-6fw5-9hq8-w87g
  • [2]Fix Commit 3831a0661514c91d99971052f983552556880402
  • [3]@graphql-tools/executor-legacy-ws Release 1.1.35
  • [4]NVD CVE-2026-103921 Detail
  • [5]CVE.org CVE-2026-103921 Record

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
3 views•5 min read
•about 2 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
7 views•7 min read
•about 3 hours ago•CVE-2026-105753
6.5

CVE-2026-105753: Reachable Assertion in vLLM Multimodal IPC Cache Leading to Denial of Service

A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.

Alon Barad
Alon Barad
7 views•5 min read
•about 4 hours ago•CVE-2026-105750
5.9

CVE-2026-105750: Local File Disclosure in Docling via Permissive HTML Rendering Requests Filter

CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.

Alon Barad
Alon Barad
8 views•7 min read
•about 5 hours ago•CVE-2026-102598
6.3

CVE-2026-102598: Remote Denial of Service via NTFS Alternate Data Stream Bypass in Werkzeug safe_join

CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.

Alon Barad
Alon Barad
10 views•7 min read
•about 9 hours ago•CVE-2026-103918
6.5

CVE-2026-103918: Prototype Injection and Denial of Service in oRPC @orpc/zod Smart Coercion Engine

CVE-2026-103918 is a medium-severity vulnerability within the @orpc/zod smart coercion plugin in oRPC. Prior to version 1.14.10, the package fails to sanitize untrusted input keys when performing pre-validation type coercion, allowing prototype injection on the returned request object and Denial of Service.

Amit Schendel
Amit Schendel
11 views•6 min read