CVE-2026-47707
- EPSS 0.42%
- Veröffentlicht 04.06.2026 14:12:49
- Zuletzt bearbeitet 05.06.2026 17:38:44
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts...
CVE-2026-45739
- EPSS 0.22%
- Veröffentlicht 04.06.2026 14:09:03
- Zuletzt bearbeitet 05.06.2026 18:43:20
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive head...
CVE-2026-47706
- EPSS 0.3%
- Veröffentlicht 04.06.2026 14:06:48
- Zuletzt bearbeitet 05.06.2026 17:37:58
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circu...
CVE-2026-35523
- EPSS 0.42%
- Veröffentlicht 07.04.2026 15:58:17
- Zuletzt bearbeitet 17.04.2026 20:37:20
Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler does not verify that a connection_...
CVE-2026-35526
- EPSS 0.27%
- Veröffentlicht 07.04.2026 15:23:36
- Zuletzt bearbeitet 17.04.2026 20:37:10
Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graphql-ws protocols allocate an asyncio.Task and associated Operation obje...