GHSA-6fw5-9hq8-w87g

Suggest an improvement
Source
https://github.com/advisories/GHSA-6fw5-9hq8-w87g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6fw5-9hq8-w87g/GHSA-6fw5-9hq8-w87g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6fw5-9hq8-w87g
Aliases
Published
2026-10-05T22:56:56Z
Modified
2026-10-05T23:15:03Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
Details

Impact

buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.

Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACY_WS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.

Browser WebSocket clients are unaffected by this option (browsers always validate certificates).

Patches

Upgrade to @graphql-tools/executor-legacy-ws@1.1.35 or later (and @graphql-tools/url-loader@9.1.9 or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.

Workarounds

  • Prefer the modern graphql-ws / SubscriptionProtocol.WS path where possible.
  • Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use ws:// only on trusted networks.
  • Supply a custom webSocketImpl that enforces certificate validation.
Database specific
{
    "cwe_ids":  [
        "CWE-295"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T22:56:56Z",
    "nvd_published_at":  "2026-10-01T17:17:19Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @graphql-tools/executor-legacy-ws

Package

Name
@graphql-tools/executor-legacy-ws
View open source insights on deps.dev
Purl
pkg:npm/%40graphql-tools/executor-legacy-ws

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.1.35

Database specific

last_known_affected_version_range
"<= 1.1.34"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6fw5-9hq8-w87g/GHSA-6fw5-9hq8-w87g.json"