Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1946
  • PyPI/strawberry-graphql
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution 07 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2284
  • PyPI/strawberry-graphql
See record for full details 04 Jun
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2283
  • PyPI/strawberry-graphql
See record for full details 04 Jun
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2282
  • PyPI/strawberry-graphql
See record for full details 04 Jun
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fr49-mhgj-crfc
  • PyPI/strawberry-graphql
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification 04 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-qfwv-87qj-98xq
  • PyPI/strawberry-graphql
Strawberry GraphQL has a Circular Fragment Reference DOS 04 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-x97m-qp5c-w9xj
  • PyPI/strawberry-graphql
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs 19 May
  • Fix available
  • Severity - 3.1 (Low)
PYSEC-2026-133
  • PyPI/strawberry-graphql
See record for full details 07 Apr
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-134
  • PyPI/strawberry-graphql
See record for full details 07 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-hv3w-m4g2-5x77
  • PyPI/strawberry-graphql
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions 06 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-vpwc-v33q-mq89
  • PyPI/strawberry-graphql
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol 06 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-5xh2-23cc-5jc6
  • PyPI/strawberry-graphql
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution 09 Jan 2025
  • Fix available
  • Severity - 3.7 (Low)
GHSA-79gp-q4wv-33fr
  • PyPI/strawberry-graphql
Cross-Site Request Forgery (CSRF) in strawberry-graphql 25 Sep 2024
  • Fix available
  • Severity - 4.8 (Medium)
PYSEC-2024-171
  • PyPI/strawberry-graphql
  • github.com/strawberry-graphql/strawberry
See record for full details 25 Sep 2024
  • Fix available
  • Severity - 8.0 (High)