CVE-2026-23735 affects GraphQL Modules versions 2.2.1 to before 2.4.1 and 3.1.1, where parallel requests can lead to context mix-up in services when using @ExecutionContext(). This vulnerability, rated 8.7 HIGH, allows for information disclosure or manipulation as authentication tokens or other sensitive data from one request could be exposed to or used by another. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Patches are available in versions 2.4.1 and 3.1.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Graphql-Hive | Graphql-Modules | >= 2.2.1, < 2.4.1, >= 3.0.0, < 3.1.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.