CVE-2026-45739: Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Strawberry’s bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as Authorization: Bearer <token>, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45739 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →