Junglewise Threat Intelligence

CVE-2026-35523: strawberry-graphql authentication bypass in legacy WebSocket subprotocol

CVE-2026-35523 · Severity: high · CVSS 7.5 · Published 2026-04-06

Technologies: strawberry-graphql (PyPI). Vendors: PyPI.

Executive brief

Strawberry is a Python library used to build GraphQL interfaces for web applications. A security flaw in its WebSocket handling allows unauthorized users to bypass authentication checks when accessing real-time data subscriptions. This could lead to the exposure of sensitive information that should only be accessible to logged-in users.

Technical details

Strawberry GraphQL (up to version 0.312.2) contains a missing authentication check (CWE-306) in its legacy 'graphql-ws' WebSocket subprotocol handler. The handler fails to verify that a 'connection_init' handshake has been completed before processing 'start' (subscription) messages. An attacker can exploit this by connecting via the legacy subprotocol and sending a subscription request directly, effectively skipping the 'on_ws_connect' authentication hook. While the newer 'graphql-transport-ws' protocol is not affected, both are enabled by default. The vulnerability is patched in version 0.312.3; users can also mitigate the risk by explicitly disabling the legacy subprotocol in their router configuration.

Affected products

  • strawberry-graphql strawberry-graphql <= 0.312.2

Timeline

  • 2026-04-04: disclosed: Initial disclosure by maintainers
  • 2026-04-06: advisory: GitHub Advisory published
  • 2026-04-07: other: NVD publication

References

Related threats