Insertion of Sensitive Information Into Sent Data Affecting strawberry-graphql package, versions [0.288.4, 0.315.4)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-STRAWBERRYGRAPHQL-16771095
  • published20 May 2026
  • disclosed19 May 2026
  • creditLeander Schroer

Introduced: 19 May 2026

NewCVE-2026-45739  (opens in a new tab)
CWE-201  (opens in a new tab)

How to fix?

Upgrade strawberry-graphql to version 0.315.4 or higher.

Overview

strawberry-graphql is an A library for creating GraphQL APIs

Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data via the graphiql template. An attacker can obtain sensitive HTTP header values by enticing a user to enter confidential information into the headers editor and then causing the resulting URL to be exposed through browser history, copied links, or server/proxy/CDN logs.

Note: This is only exploitable if the default browser-based IDE is enabled and a user manually enters sensitive data into the headers editor.

Workaround

This vulnerability can be mitigated by disabling the bundled IDE in production or by providing a custom GraphiQL template that does not serialize header values into the URL.

CVSS Base Scores

version 4.0
version 3.1