Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Strawberry

First CVE: May 22, 2009Active for: 17 yearsTotal CVEs: 6

Strawberry is a Python-based GraphQL framework with a narrowly scoped but prominently adopted product line centered on the Strawberry GraphQL library. Its vulnerability profile clusters around resource-handling and information-disclosure weakness classes—including uncontrolled resource consumption, path traversal, and exposure of sensitive data—that arise from the framework's role in parsing and serving GraphQL queries. Public exploit code has emerged for vulnerabilities in this space; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Strawberry over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2009
17 years ago
Most Recent CVE
Jun 4, 2026
50 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-1774HIGH
Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file pa
May 22, 20099.342NOYES
CVE-2026-35526HIGH
Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graph
Apr 7, 20267.526NONO
CVE-2026-47707MEDIUM
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative
Jun 4, 20265.325NONO
CVE-2026-35523HIGH
Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The le
Apr 7, 20267.525NONO
CVE-2026-47706MEDIUM
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a la
Jun 4, 20265.323NONO
CVE-2026-45739MEDIUM
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor
Jun 4, 20264.322NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (83.3%)
Unknown1 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High0 (0.0%)
Unknown1 (16.7%)
User Interaction
None4 (66.7%)
Unknown1 (16.7%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (83.3%)
Unknown1 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Strawberry.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Strawberry — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Strawberry's Products

View all 2 CNAs →

Top CWEs