Strawberry GraphQL versions prior to 0.312.3 contain a subscription denial-of-service vulnerability in WebSocket handlers for both graphql-transport-ws and legacy graphql-ws protocols. The vulnerability stems from the failure to enforce limits on active subscriptions per connection, allowing unauthenticated attackers to spawn unlimited asyncio tasks and async generators with malicious subscribe messages. The vulnerability presents a HIGH severity risk with a CVSS score of 7.5, requiring only network access with no authentication or user interaction. The attack vector is straightforward, leveraging a single WebSocket connection to flood the server with subscription requests, resulting in linear memory consumption and eventual service degradation or out-of-memory crashes. While the vulnerability does not compromise confidentiality or integrity, the availability impact is substantial. There is no evidence of active exploitation in the wild, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.000630000 indicates relatively low probabilistic exploitation likelihood compared to the broader CVE landscape. Organizations running Strawberry GraphQL should prioritize patching to version 0.312.3 or later to mitigate this resource exhaustion risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.312.3CPE matchmatch criteria | cpe:2.3:a:strawberry:strawberry_graphql:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.