Vulnerability in Strawberry GraphQL Library Affects Subscription Handling
CVE-2026-107727
3.7LOW
What is CVE-2026-107727?
The Strawberry GraphQL library contains a flaw in its legacy graphql-ws subscription handler that fails to correctly manage completed operations. Specifically, from versions 0.312.3 to 0.327.1, the handler retains naturally completed operations in memory, allowing clients on persistent WebSocket connections to exceed subscription limits. This improper resource management results in legitimate operations being rejected with a 'Subscription limit reached' error even after previous subscriptions have completed. Users are advised to update to version 0.327.2 or above to mitigate this issue.
Affected Version(s)
strawberry >= 0.312.3, < 0.327.2
