Vulnerabilities

Last updated 39 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
strawberry-graphql Strawberry legacy graphql-ws retains naturally completed subscription slots Low Risk 3.7 7 hours ago 7 hours ago
strawberry-graphql Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High Risk 7.5 7 hours ago 7 hours ago
strawberry-graphql Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs Low Risk 3.1 4 months ago 2 months ago
strawberry-graphql Strawberry GraphQL has a Circular Fragment Reference DOS Medium Risk 5.3 4 months ago 2 months ago
strawberry-graphql Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification Medium Risk 5.3 4 months ago 2 months ago
strawberry-graphql No summary available Medium Risk 4.3 4 months ago 2 months ago
strawberry-graphql No summary available Medium Risk 5.3 4 months ago 2 months ago
strawberry-graphql No summary available Medium Risk 5.3 4 months ago 2 months ago
strawberry-graphql Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution Low Risk 3.7 1 year ago 3 months ago
strawberry-graphql Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution Low Risk 3.7 3 months ago 3 months ago
strawberry-graphql strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol High Risk 7.5 6 months ago 4 months ago
strawberry-graphql strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions High Risk 7.5 6 months ago 4 months ago
strawberry-graphql No summary available High Risk 7.5 6 months ago 4 months ago
strawberry-graphql No summary available High Risk 7.5 6 months ago 4 months ago
strawberry-graphql Cross-Site Request Forgery (CSRF) in strawberry-graphql Medium Risk 4.6 2 years ago 1 year ago
strawberry-graphql No summary available High Risk 8.0 2 years ago 1 year ago