Vulnerability GHSA-6fw5-9hq8-w87g
Summary
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor
Details
Impact
buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.
Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACY_WS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.
Browser WebSocket clients are unaffected by this option (browsers always validate certificates).
Patches
Upgrade to @graphql-tools/[email protected] or later (and @graphql-tools/[email protected] or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.
Workarounds
- Prefer the modern
graphql-ws/SubscriptionProtocol.WSpath where possible. - Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use
ws://only on trusted networks. - Supply a custom
webSocketImplthat enforces certificate validation.