Executive brief
Strawberry is a Python library used to build GraphQL interfaces for web applications. A security flaw in its WebSocket handling allows unauthorized users to bypass authentication checks when accessing real-time data subscriptions. This could lead to the exposure of sensitive information that should only be accessible to logged-in users.
Technical details
Strawberry GraphQL (up to version 0.312.2) contains a missing authentication check (CWE-306) in its legacy 'graphql-ws' WebSocket subprotocol handler. The handler fails to verify that a 'connection_init' handshake has been completed before processing 'start' (subscription) messages. An attacker can exploit this by connecting via the legacy subprotocol and sending a subscription request directly, effectively skipping the 'on_ws_connect' authentication hook. While the newer 'graphql-transport-ws' protocol is not affected, both are enabled by default. The vulnerability is patched in version 0.312.3; users can also mitigate the risk by explicitly disabling the legacy subprotocol in their router configuration.
Affected products
- strawberry-graphql strawberry-graphql <= 0.312.2
Timeline
- 2026-04-04: disclosed: Initial disclosure by maintainers
- 2026-04-06: advisory: GitHub Advisory published
- 2026-04-07: other: NVD publication