Synchronous Field Resolver Vulnerability in Strawberry GraphQL Library from Strawberry Inc.
CVE-2026-107728

7.5HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107728?

The Strawberry GraphQL library, utilized for creating GraphQL APIs, contains a vulnerability in its synchronous field resolver logic. The issue arises when the function has_permission() is implemented as a standard function but returns an awaitable object. Due to faulty permission check handling in the supports_sync context, the awaitable is not properly awaited. Consequently, this oversight allows the protected resolver to execute even when permissions should effectively deny access. This vulnerability affects versions from 0.217.0 up to 0.326.1 and is resolved in version 0.326.1. It is crucial for users to update to mitigate potential unauthorized access risks.

Affected Version(s)

strawberry >= 0.217.0, < 0.326.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.