@graphql-tools/executor-legacy-ws@1.1.20-alpha-20251007153941-101d5120317eaf114e18d78b366db7ddacb3d150

A set of utils for faster development of GraphQL tools

Direct Vulnerabilities

Known vulnerabilities in the @graphql-tools/executor-legacy-ws package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Improper Certificate Validation

@graphql-tools/executor-legacy-ws is an A set of utils for faster development of GraphQL tools

Affected versions of this package are vulnerable to Improper Certificate Validation via a hardcoded rejectUnauthorized: false in buildWSLegacyExecutor, which unconditionally disables TLS certificate validation for all wss:// connections and cannot be overridden by callers. An attacker positioned between the client and the server can intercept or tamper with the WebSocket traffic by presenting an invalid or self-signed certificate that is silently accepted. This exposes the full contents of GraphQL subscription traffic to a MitM attacker, resulting in high confidentiality and integrity impact.

How to fix Improper Certificate Validation?

Upgrade @graphql-tools/executor-legacy-ws to version 1.1.35 or higher.

<1.1.35