OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103921

HIGH · CVSS 7.4 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The GraphQL Tools library, prior to version 1.1.35, contains a vulnerability in the executor-legacy-ws buildWSLegacyExecutor() function that disables TLS certificate validation for Node.js connections to WebSocket endpoints. This flaw allows an attacker to intercept connections and potentially disclose sensitive authentication information or modify subscription data. Developers utilizing this library for Node.js applications should prioritize updating to version 1.1.35 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103921
Severity
HIGH
CVSS
7.4
EPSS
0.27%

Original NVD Description

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js connections to wss:// endpoints. Applications using the executor directly, or url-loader with SubscriptionProtocol.LEGACY_WS, can therefore accept an attacker-controlled certificate when a network-positioned attacker intercepts the connection. Authentication material in connectionParams or headers can be disclosed, and subscription data can be modified. Browser WebSocket clients are unaffected because browsers enforce certificate validation. This issue is fixed in version 1.1.35.