buildWSLegacyExecutor() in @graphql-tools/executor-legacy-ws previously hardcoded rejectUnauthorized: false when creating WebSocket connections over WSS. This disabled TLS certificate validation, allowing a network-positioned attacker to perform a Man-in-the-Middle (MITM) attack against applications that use this executor with a wss:// endpoint. Credentials passed via connectionParams or headers could be intercepted, and subscription data could be tampered with.
Who is impacted: Applications using @graphql-tools/executor-legacy-ws (directly or via @graphql-tools/url-loader with SubscriptionProtocol.LEGACYWS) to connect to a wss:// endpoint from Node.js while sending authentication material over the connection.
Browser WebSocket clients are unaffected by this option (browsers always validate certificates).
// patchesUpgrade to @graphql-tools/executor-legacy-ws@1.1.35 or later (and @graphql-tools/url-loader@9.1.9 or later if you use the loader). TLS certificate validation is enabled by default. Callers that intentionally use self-signed certificates in trusted environments can opt out with rejectUnauthorized: false.
// workarounds- Prefer the modern graphql-ws / SubscriptionProtocol.WS path where possible.
- Until upgraded, avoid sending secrets over legacy WSS connections, or terminate TLS at a trusted proxy and use ws:// only on trusted networks.
- Supply a custom webSocketImpl that enforces certificate validation.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- None