<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>GraphQL Tools - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/graphql-tools/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:46:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/graphql-tools/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>TLS Validation Bypass in GraphQL Tools Legacy WebSocket Executor</title><link>https://feed.craftedsignal.io/briefs/2026-10-graphql-tls-validation/</link><pubDate>Tue, 06 Oct 2026 00:46:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-graphql-tls-validation/</guid><description>The @graphql-tools/executor-legacy-ws package incorrectly disables TLS certificate validation for WSS connections, enabling MITM attacks that can lead to credential interception.</description><content:encoded><![CDATA[<p>The package <code>@graphql-tools/executor-legacy-ws</code> contains a vulnerability (CVE-2026-103921) where the <code>buildWSLegacyExecutor()</code> function explicitly sets <code>rejectUnauthorized: false</code> for WebSocket connections. This implementation hardcodes the disabling of TLS certificate verification, effectively neutralizing the security provided by <code>wss://</code> (WebSocket Secure) endpoints. When a Node.js application uses this executor to connect to a GraphQL server, it fails to verify the server's identity.</p>
<p>This flaw creates an opportunity for network-positioned attackers to conduct Man-in-the-Middle (MITM) attacks. By presenting a fraudulent certificate, an attacker can decrypt the connection, intercept sensitive authentication credentials sent via <code>connectionParams</code> or headers, and manipulate subscription data in transit. This impact is limited to Node.js environments; browser-based WebSocket implementations are inherently protected as they perform their own TLS validation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The target application initiates a connection to a GraphQL server using <code>@graphql-tools/executor-legacy-ws</code> via a <code>wss://</code> URI.</li>
<li>The <code>buildWSLegacyExecutor</code> function initializes the WebSocket connection with <code>rejectUnauthorized: false</code>.</li>
<li>A network-positioned attacker performs an ARP spoofing, DNS hijacking, or BGP redirection to intercept traffic destined for the GraphQL server.</li>
<li>The attacker presents an untrusted or self-signed TLS certificate to the client application.</li>
<li>The vulnerable client accepts the fraudulent certificate without error due to the disabled validation logic.</li>
<li>The client transmits authentication tokens or secrets to the attacker, believing it is communicating with the legitimate server.</li>
<li>The attacker intercepts the transmitted secrets or modifies the GraphQL subscription stream.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the interception of sensitive application credentials and the manipulation of data streams within GraphQL subscriptions. This affects any backend service in the Node.js ecosystem utilizing the legacy WebSocket executor for secure communication. The scope includes any application that passes authentication tokens or session identifiers through the connection metadata.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the vulnerable packages immediately to versions that enforce TLS validation by default: <code>@graphql-tools/executor-legacy-ws@1.1.35</code> and <code>@graphql-tools/url-loader@9.1.9</code>.</li>
<li>Perform an audit of internal codebases to identify usage of <code>SubscriptionProtocol.LEGACY_WS</code> and confirm it has been updated to the non-vulnerable version.</li>
<li>Implement network-layer monitoring to detect unauthorized interception or TLS inspection artifacts if immediate patching is not possible.</li>
<li>Transition to the modern <code>graphql-ws</code> protocol library as a long-term architectural mitigation to avoid legacy implementation risks.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cve</category><category>nodejs</category><category>graphql</category></item></channel></rss>