GHSA-6fw5-9hq8-w87gHighCVSS 7.4

GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor

Published
October 5, 2026
Last Modified
October 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.

Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACY_WS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.

Browser WebSocket clients are unaffected by this option (browsers always validate certificates).

Patches

Upgrade to @graphql-tools/[email protected] or later (and @graphql-tools/[email protected] or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.

Workarounds

  • Prefer the modern graphql-ws / SubscriptionProtocol.WS path where possible.
  • Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use ws:// only on trusted networks.
  • Supply a custom webSocketImpl that enforces certificate validation.

🎯 Affected products1

  • npm/@graphql-tools/executor-legacy-ws:<= 1.1.34

🔗 References (6)