Junglewise Threat Intelligence

CVE-2026-45739: Strawberry GraphQL sensitive information leak in GraphiQL template

CVE-2026-45739 · Severity: low · CVSS 3.1 · Published 2026-06-04

Technologies: strawberry-graphql (PyPI). Vendors: PyPI.

Executive brief

Strawberry GraphQL is a library used to build GraphQL APIs. A vulnerability in its built-in developer interface (GraphiQL) causes sensitive information, such as login tokens or authorization headers, to be saved directly into the browser's URL. This could lead to the accidental exposure of credentials through browser history, shared links, or server logs, potentially allowing unauthorized access to the API if those links or logs are intercepted.

Technical details

A vulnerability exists in the GraphiQL template bundled with Strawberry GraphQL versions 0.288.4 through 0.315.3. The implementation of the 'URL sharing' feature incorrectly includes the contents of the headers editor in the browser's URL query string via 'history.replaceState' on every keystroke. Consequently, sensitive headers like 'Authorization: Bearer <token>' are persisted in the URL. This results in sensitive data being exposed in browser history, server/proxy/CDN access logs, and any shared links. The issue is resolved in version 0.315.4 by removing the automatic update of the URL when headers are edited, while still allowing headers to be persisted via localStorage.

Affected products

  • Strawberry GraphQL strawberry-graphql 0.288.4 - 0.315.3

Timeline

  • 2026-01-12: other: Vulnerable URL sharing feature introduced in PR #2842
  • 2026-05-06: disclosed: Issue reported to maintainers via GitHub issue #4398
  • 2026-05-12: patched: Version 0.315.4 released
  • 2026-05-13: advisory: GitHub Security Advisory published
  • 2026-06-04: other: CVE-2026-45739 assigned/published in NVD

References

Related threats