npm package report

Is @graphql-tools/executor-legacy-ws safe?

1 known vulnerability, worst severity HIGH.

// reach

5 direct dependencies

2 carry known advisories, worst HIGH

0 packages depend on it

an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


    cvss
    0.0
    high

    severity out of 10

    epss
    0.00%
    low

    chance of exploitation in 30 days, 17th percentile of all CVEs

    xyz score
    not scored

    CyberXYZ composite out of 10

    fig. 01 — GHSA-6fw5-9hq8-w87g, the advisory selected below

    // 1 advisories

    GHSA-6fw5-9hq8-w87g

    HIGHCVE-2026-103921
    // impact

    buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.

    Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACYWS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.

    Browser WebSocket clients are unaffected by this option (browsers always validate certificates).

    // patches

    Upgrade to @graphql-tools/executor-legacy-ws@1.1.35 or later (and @graphql-tools/url-loader@9.1.9 or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.

    // workarounds
    • Prefer the modern graphql-ws / SubscriptionProtocol.WS path where possible.
    • Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use ws:// only on trusted networks.
    • Supply a custom webSocketImpl that enforces certificate validation.
    // cvss v3.1 vector

    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

    Attack vector
    Network
    Attack complexity
    High
    Privileges required
    None
    User interaction
    None
    Scope
    Unchanged
    Confidentiality
    High
    Integrity
    High
    Availability
    None

    Checked 2026-10-06 at 02:03 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.