Strawberry is a Python-based GraphQL framework with a narrowly scoped but prominently adopted product line centered on the Strawberry GraphQL library. Its vulnerability profile clusters around resource-handling and information-disclosure weakness classes—including uncontrolled resource consumption, path traversal, and exposure of sensitive data—that arise from the framework's role in parsing and serving GraphQL queries. Public exploit code has emerged for vulnerabilities in this space; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Strawberry over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1774HIGH Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file pa | May 22, 2009 | 9.3 | 42 | NO | YES |
CVE-2026-35526HIGH Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription handlers for both the graphql-transport-ws and legacy graph | Apr 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-47707MEDIUM Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative | Jun 4, 2026 | 5.3 | 25 | NO | NO |
CVE-2026-35523HIGH Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscription endpoints. The le | Apr 7, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-47706MEDIUM Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a la | Jun 4, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-45739MEDIUM Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor | Jun 4, 2026 | 4.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Strawberry.
Media articles that mention a CVE ID that affects a product developed by Strawberry — matched by CVE ID, not by vendor name.