buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.
Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACY_WS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.
Browser WebSocket clients are unaffected by this option (browsers always validate certificates).
Upgrade to @graphql-tools/executor-legacy-ws@1.1.35 or later (and @graphql-tools/url-loader@9.1.9 or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.
graphql-ws / SubscriptionProtocol.WS path where possible.ws:// only on trusted networks.webSocketImpl that enforces certificate validation.{
"cwe_ids": [
"CWE-295"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-05T22:56:56Z",
"nvd_published_at": "2026-10-01T17:17:19Z",
"severity": "HIGH"
}