Synchronous Field Resolver Vulnerability in Strawberry GraphQL Library from Strawberry Inc.
CVE-2026-107728
7.5HIGH
What is CVE-2026-107728?
The Strawberry GraphQL library, utilized for creating GraphQL APIs, contains a vulnerability in its synchronous field resolver logic. The issue arises when the function has_permission() is implemented as a standard function but returns an awaitable object. Due to faulty permission check handling in the supports_sync context, the awaitable is not properly awaited. Consequently, this oversight allows the protected resolver to execute even when permissions should effectively deny access. This vulnerability affects versions from 0.217.0 up to 0.326.1 and is resolved in version 0.326.1. It is crucial for users to update to mitigate potential unauthorized access risks.
Affected Version(s)
strawberry >= 0.217.0, < 0.326.1
