CVE-2026-103921: GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.
Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACY_WS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.
Browser WebSocket clients are unaffected by this option (browsers always validate certificates).
References
- github.com/advisories/GHSA-6fw5-9hq8-w87g
- github.com/ardatan/graphql-tools/commit/3831a0661514c91d99971052f983552556880402
- github.com/ardatan/graphql-tools/pull/8426
- github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/executor-legacy-ws@1.1.35
- github.com/ardatan/graphql-tools/security/advisories/GHSA-6fw5-9hq8-w87g
- nvd.nist.gov/vuln/detail/CVE-2026-103921
Code Behaviors & Features
Detect and mitigate CVE-2026-103921 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →