Strawberry GraphQL versions prior to 0.312.3 contain an authentication bypass vulnerability in WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler fails to verify connection initialization before processing subscription messages, allowing attackers to circumvent the on_ws_connect authentication hook by sending a start message directly without completing the required handshake. The vulnerability carries a CVSS score of 7.5 (High) with a network-based attack vector requiring no special privileges or user interaction. While the attack complexity is low and could result in unauthorized information disclosure, integrity and availability impacts are not present. The EPSS score of 0.00125 indicates this vulnerability has relatively low predicted exploitation probability compared to the broader CVE landscape. There is currently no evidence of active exploitation or public exploit code availability for this vulnerability. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog, and community attention remains minimal, as reflected by its inactive status on threat monitoring platforms. Organizations should prioritize updating to version 0.312.3 to eliminate this authentication bypass vector, particularly for deployments relying on GraphQL WebSocket subscriptions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.312.3CPE matchmatch criteria | cpe:2.3:a:strawberry:strawberry_graphql:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.