


Perceptive Security
SOC/SIEM Consultancy

Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authentication bypass on WebSocket subscripti…
Published:
6 April 2026 at 22:00:00
Alert date:
7 April 2026 at 18:06:01
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
Strawberry GraphQL library versions up to 0.312.3 contain an authentication bypass vulnerability in WebSocket subscription endpoints. The legacy graphql-ws subprotocol handler fails to verify connection_init handshake completion before processing start messages. Remote attackers can exploit this by connecting with the graphql-ws subprotocol and sending start messages directly, bypassing the on_ws_connect authentication hook without sending connection_init. The vulnerability is fixed in version 0.312.3.
Technical details
Mitigation steps:
Affected products:
Strawberry GraphQL
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35523
https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-vpwc-v33q-mq89
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
