VendorsStrawberrystrawberry_graphqlall versions
Vulnerabilities

Strawberry GraphQL

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-35523
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocol
Published 2026-04-07 · Analyzed
7.5EPSS 0.006
CVE-2026-35526
Strawberry GraphQL affected by a Denial of Service via unbounded WebSocket subscriptions
Published 2026-04-07 · Analyzed
7.5EPSS 0.005
CVE-2026-47707
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Published 2026-06-04 · Analyzed
5.3EPSS 0.007
CVE-2026-47706
Strawberry GraphQL has a Circular Fragment Reference DOS
Published 2026-06-04 · Analyzed
5.3EPSS 0.004
CVE-2026-45739
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Published 2026-06-04 · Analyzed
4.3EPSS 0.004