Junglewise Threat Intelligence

Envelop graphql-modules race condition in context injection

Severity: medium · CVSS 4 · Published 2026-01-21

Vendors: npm.

Executive brief

@envelop/graphql-modules is a GraphQL plugin that integrates module-based architecture with GraphQL servers. When multiple requests are processed in parallel, the plugin incorrectly mixes up request-specific data (context) between them, causing one user's request to leak information from another's. This is particularly dangerous in applications handling sensitive data like authentication tokens or user identifiers.

Technical details

A race condition exists in @envelop/graphql-modules when executing parallel requests through services that use @ExecutionContext() injection from singleton providers. The vulnerability arises because the useGraphQLModules plugin bypasses the async_hooks-based context isolation that was implemented in the underlying graphql-modules library (versions 2.4.1+ and 3.1.1+). When two or more concurrent requests trigger the same injected service, the context injector reads from a shared, non-isolated context pool rather than the request-specific context, causing request data (such as requestId) to bleed between parallel executions. An attacker can exploit this by sending parallel requests to trigger context mixing; the more concurrent traffic, the higher the probability of exploitation. The vulnerability is fixed in @envelop/graphql-modules 9.1.0.

Affected products

  • The Graph Foundation @envelop/graphql-modules <= 9.0.0

Timeline

  • 2026-01-21: disclosed
  • 2026-01-21: patched: Fixed in version 9.1.0

References