Vulnerability PYSEC-2026-2282

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 months ago
June 04, 2026 at 03:16 PM UTC
No summary available
0.288.4 - 0.315.3
0.288.4 - 0.315.3

Details

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as Authorization: Bearer <token>, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue.

Impacted packages

Timeline

Published
4 months ago
June 04, 2026 at 03:16 PM UTC
Fixed (0.315.4)
5 months ago
May 12, 2026 at 06:35 PM UTC
Last Modified
2 months ago
July 13, 2026 at 07:15 AM UTC