To report a security vulnerability, please use the Tidelift security contact. Tidelift will coordinate the fix and disclosure.
Security: strawberry-graphql/strawberry
Security
.github/SECURITY.md
-
Authentication bypass in strawberry-graphql via legacy graphql-ws WebSocket subprotocolGHSA-vpwc-v33q-mq89 published
Apr 4, 2026 by patrick91High -
Denial of Service via unbounded WebSocket subscriptionsGHSA-hv3w-m4g2-5x77 published
Apr 4, 2026 by patrick91High -
Type resolution vulnerability in node interface allows potential data leakage through incorrect type resolutionGHSA-5xh2-23cc-5jc6 published
Jan 9, 2025 by patrick91Low -
Cross-Site Request Forgery (CSRF) in strawberry-graphqlGHSA-79gp-q4wv-33fr published
Sep 25, 2024 by patrick91Moderate
Learn more about advisories related to strawberry-graphql/strawberry in the GitHub Advisory Database