TLS Validation Bypass in GraphQL Tools Legacy WebSocket Executor
The @graphql-tools/executor-legacy-ws package incorrectly disables TLS certificate validation for WSS connections, enabling MITM attacks that can lead to credential interception.
CVE search metadata
CVE search record: CVE-2026-103921. Severity: high. CVSS: 7.4. EPSS: 0.27%. KEV: no. Product: @graphql-tools/executor-legacy-ws (<= 1.1.34), @graphql-tools/url-loader (< 9.1.9). Brief: TLS Validation Bypass in GraphQL Tools Legacy WebSocket Executor. Brief link: https://feed.craftedsignal.io/briefs/2026-10-graphql-tls-validation/
The package @graphql-tools/executor-legacy-ws contains a vulnerability (CVE-2026-103921) where the buildWSLegacyExecutor() function explicitly sets rejectUnauthorized: false for WebSocket connections. This implementation hardcodes the disabling of TLS certificate verification, effectively neutralizing the security provided by wss:// (WebSocket Secure) endpoints. When a Node.js application uses this executor to connect to a GraphQL server, it fails to verify the server's identity.
This flaw creates an opportunity for network-positioned attackers to conduct Man-in-the-Middle (MITM) attacks. By presenting a fraudulent certificate, an attacker can decrypt the connection, intercept sensitive authentication credentials sent via connectionParams or headers, and manipulate subscription data in transit. This impact is limited to Node.js environments; browser-based WebSocket implementations are inherently protected as they perform their own TLS validation.
Attack Chain
- The target application initiates a connection to a GraphQL server using
@graphql-tools/executor-legacy-wsvia awss://URI. - The
buildWSLegacyExecutorfunction initializes the WebSocket connection withrejectUnauthorized: false. - A network-positioned attacker performs an ARP spoofing, DNS hijacking, or BGP redirection to intercept traffic destined for the GraphQL server.
- The attacker presents an untrusted or self-signed TLS certificate to the client application.
- The vulnerable client accepts the fraudulent certificate without error due to the disabled validation logic.
- The client transmits authentication tokens or secrets to the attacker, believing it is communicating with the legitimate server.
- The attacker intercepts the transmitted secrets or modifies the GraphQL subscription stream.
Impact
Successful exploitation allows for the interception of sensitive application credentials and the manipulation of data streams within GraphQL subscriptions. This affects any backend service in the Node.js ecosystem utilizing the legacy WebSocket executor for secure communication. The scope includes any application that passes authentication tokens or session identifiers through the connection metadata.
Recommendation
- Upgrade the vulnerable packages immediately to versions that enforce TLS validation by default:
@graphql-tools/executor-legacy-ws@1.1.35and@graphql-tools/url-loader@9.1.9. - Perform an audit of internal codebases to identify usage of
SubscriptionProtocol.LEGACY_WSand confirm it has been updated to the non-vulnerable version. - Implement network-layer monitoring to detect unauthorized interception or TLS inspection artifacts if immediate patching is not possible.
- Transition to the modern
graphql-wsprotocol library as a long-term architectural mitigation to avoid legacy implementation risks.
Immediate actions
Upgrade @graphql-tools/executor-legacy-ws to 1.1.35 or higher and @graphql-tools/url-loader to 9.1.9 or higher.
Mitigations
Enforce TLS certificate validation at the infrastructure level by terminating WSS at a trusted proxy.
CVE-2026-103921