Vulnerability in Strawberry GraphQL Library Affects Subscription Handling
CVE-2026-107727

3.7LOW

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107727?

The Strawberry GraphQL library contains a flaw in its legacy graphql-ws subscription handler that fails to correctly manage completed operations. Specifically, from versions 0.312.3 to 0.327.1, the handler retains naturally completed operations in memory, allowing clients on persistent WebSocket connections to exceed subscription limits. This improper resource management results in legitimate operations being rejected with a 'Subscription limit reached' error even after previous subscriptions have completed. Users are advised to update to version 0.327.2 or above to mitigate this issue.

Affected Version(s)

strawberry >= 0.312.3, < 0.327.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.