{"id":"GHSA-6fw5-9hq8-w87g","summary":"GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor","details":"## Impact\n\n`buildWSLegacyExecutor()` in `@graphql-tools/executor-legacy-ws` previously hardcoded `rejectUnauthorized: false` when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a `wss://` endpoint. Credentials passed via `connectionParams` or `headers` could be intercepted, and subscription data could be tampered with.\n\n**Who is impacted:** Applications using `@graphql-tools/executor-legacy-ws` (directly or via `@graphql-tools/url-loader` with `SubscriptionProtocol.LEGACY_WS`) to connect to a `wss://` endpoint from Node.js while sending authentication material over the connection.\n\nBrowser WebSocket clients are unaffected by this option (browsers always validate certificates).\n\n## Patches\n\nUpgrade to `@graphql-tools/executor-legacy-ws@1.1.35` or later (and `@graphql-tools/url-loader@9.1.9` or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with `rejectUnauthorized: false`.\n\n## Workarounds\n\n- Prefer the modern `graphql-ws` / `SubscriptionProtocol.WS` path where possible.\n- Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use `ws://` only on trusted networks.\n- Supply a custom `webSocketImpl` that enforces certificate validation.","aliases":["CVE-2026-103921"],"modified":"2026-10-05T23:15:09.208035984Z","published":"2026-10-05T22:56:56Z","database_specific":{"github_reviewed_at":"2026-10-05T22:56:56Z","nvd_published_at":"2026-10-01T17:17:19Z","cwe_ids":["CWE-295"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ardatan/graphql-tools/security/advisories/GHSA-6fw5-9hq8-w87g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103921"},{"type":"WEB","url":"https://github.com/ardatan/graphql-tools/pull/8426"},{"type":"WEB","url":"https://github.com/ardatan/graphql-tools/commit/3831a0661514c91d99971052f983552556880402"},{"type":"PACKAGE","url":"https://github.com/ardatan/graphql-tools"},{"type":"WEB","url":"https://github.com/ardatan/graphql-tools/releases/tag/@graphql-tools/executor-legacy-ws@1.1.35"}],"affected":[{"package":{"name":"@graphql-tools/executor-legacy-ws","ecosystem":"npm","purl":"pkg:npm/%40graphql-tools/executor-legacy-ws"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.35"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.1.34","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6fw5-9hq8-w87g/GHSA-6fw5-9hq8-w87g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}