OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-103921: GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

## Impact `buildWSLegacyExecutor()` in `@graphql-tools/executor-legacy-ws` previously hardcoded `rejectUnauthorized: false` when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a `wss://` endpoint. Credentials passed via `connectionParams` or `headers` could be intercepted, and subscription data could be tampered with. **Who is impacted:** Applications using `@graphql-tools/executor-legacy-ws` (directly or via `@graphql-tools/url-loader` with `SubscriptionProtocol.LEGACY_WS`) to connect to a `wss://` endpoint from Node.js while sending authentication material over the connection. Browser WebSocket clients are unaffected by this option (browsers always validate certificates). ## Patches Upgrade to `@graphql-tools/[email protected]` or later (and `@graphql-tools/[email protected]` or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with `rejectUnauthorized: false`. ## Workarounds - Prefer the modern `graphql-ws` / `SubscriptionProtocol.WS` path where possible. - Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use `ws://` only on trusted networks. - Supply a custom `webSocketImpl` that enforces certificate validation.

Upgrade affected packages to a patched version: @graphql-tools/executor-legacy-ws 1.1.35.

Vendor
Not specified
Product
@graphql-tools/executor-legacy-ws
Exploitation
none known
Evidence
official
CVSS
7.4

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source