{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@graphql-tools/executor-legacy-ws--1.1.34/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-103921"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@graphql-tools/executor-legacy-ws (\u003c= 1.1.34)","@graphql-tools/url-loader (\u003c 9.1.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cve","nodejs","graphql"],"_cs_type":"advisory","_cs_vendors":["GraphQL Tools"],"content_html":"\u003cp\u003eThe package \u003ccode\u003e@graphql-tools/executor-legacy-ws\u003c/code\u003e contains a vulnerability (CVE-2026-103921) where the \u003ccode\u003ebuildWSLegacyExecutor()\u003c/code\u003e function explicitly sets \u003ccode\u003erejectUnauthorized: false\u003c/code\u003e for WebSocket connections. This implementation hardcodes the disabling of TLS certificate verification, effectively neutralizing the security provided by \u003ccode\u003ewss://\u003c/code\u003e (WebSocket Secure) endpoints. When a Node.js application uses this executor to connect to a GraphQL server, it fails to verify the server's identity.\u003c/p\u003e\n\u003cp\u003eThis flaw creates an opportunity for network-positioned attackers to conduct Man-in-the-Middle (MITM) attacks. By presenting a fraudulent certificate, an attacker can decrypt the connection, intercept sensitive authentication credentials sent via \u003ccode\u003econnectionParams\u003c/code\u003e or headers, and manipulate subscription data in transit. This impact is limited to Node.js environments; browser-based WebSocket implementations are inherently protected as they perform their own TLS validation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe target application initiates a connection to a GraphQL server using \u003ccode\u003e@graphql-tools/executor-legacy-ws\u003c/code\u003e via a \u003ccode\u003ewss://\u003c/code\u003e URI.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ebuildWSLegacyExecutor\u003c/code\u003e function initializes the WebSocket connection with \u003ccode\u003erejectUnauthorized: false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eA network-positioned attacker performs an ARP spoofing, DNS hijacking, or BGP redirection to intercept traffic destined for the GraphQL server.\u003c/li\u003e\n\u003cli\u003eThe attacker presents an untrusted or self-signed TLS certificate to the client application.\u003c/li\u003e\n\u003cli\u003eThe vulnerable client accepts the fraudulent certificate without error due to the disabled validation logic.\u003c/li\u003e\n\u003cli\u003eThe client transmits authentication tokens or secrets to the attacker, believing it is communicating with the legitimate server.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts the transmitted secrets or modifies the GraphQL subscription stream.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the interception of sensitive application credentials and the manipulation of data streams within GraphQL subscriptions. This affects any backend service in the Node.js ecosystem utilizing the legacy WebSocket executor for secure communication. The scope includes any application that passes authentication tokens or session identifiers through the connection metadata.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the vulnerable packages immediately to versions that enforce TLS validation by default: \u003ccode\u003e@graphql-tools/executor-legacy-ws@1.1.35\u003c/code\u003e and \u003ccode\u003e@graphql-tools/url-loader@9.1.9\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePerform an audit of internal codebases to identify usage of \u003ccode\u003eSubscriptionProtocol.LEGACY_WS\u003c/code\u003e and confirm it has been updated to the non-vulnerable version.\u003c/li\u003e\n\u003cli\u003eImplement network-layer monitoring to detect unauthorized interception or TLS inspection artifacts if immediate patching is not possible.\u003c/li\u003e\n\u003cli\u003eTransition to the modern \u003ccode\u003egraphql-ws\u003c/code\u003e protocol library as a long-term architectural mitigation to avoid legacy implementation risks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:46:04Z","date_published":"2026-10-06T00:46:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-graphql-tls-validation/","summary":"The @graphql-tools/executor-legacy-ws package incorrectly disables TLS certificate validation for WSS connections, enabling MITM attacks that can lead to credential interception.","title":"TLS Validation Bypass in GraphQL Tools Legacy WebSocket Executor","url":"https://feed.craftedsignal.io/briefs/2026-10-graphql-tls-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - @Graphql-Tools/Executor-Legacy-Ws (\u003c= 1.1.34)","version":"https://jsonfeed.org/version/1.1"}