Insecure TLS Certificate Handling in GraphQL Tools by Ardatan
CVE-2026-103921
7.4HIGH
What is CVE-2026-103921?
GraphQL Tools, a utility suite for building and mocking GraphQL schemas, is vulnerable due to the hardcoded TLS certificate rejection settings in the executor-legacy-ws buildWSLegacyExecutor() function. This oversight allows applications utilizing this executor, or the url-loader with SubscriptionProtocol.LEGACY_WS, to accept potentially malicious certificates from attackers intercepting connections. As a result, sensitive information such as authentication tokens and headers may be exposed, and the integrity of subscription data could be compromised. Users of version 1.1.35 or later are protected against this vulnerability, as it has been addressed in the latest release.
Affected Version(s)
executor-legacy-ws < 1.1.35
graphql-tools < 1.1.35
