PT-2026-3319 · Unknown · Graphql-Modules
Duckthom
·
Publicado
2026-01-16
·
Atualizado
2026-01-17
·
CVE-2026-23735
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GraphQL Modules versions 2.2.1 through 2.4.0
GraphQL Modules versions 3.1.1
Description
GraphQL Modules has an issue where, when two or more parallel requests trigger the same service, the context of the requests can become mixed up within the service when the context is injected via
@ExecutionContext(). The ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This can lead to unauthorized access or data breaches. An estimated number of potentially affected devices worldwide is not available. There are no reports of real-world incidents where this issue was exploited. The vulnerability occurs when using the @ExecutionContext() decorator. The context variable can be affected when multiple requests are processed concurrently.Recommendations
Update to GraphQL Modules version 2.4.1 or later.
Update to GraphQL Modules version 3.1.1 or later.
Exploit
Correção
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Graphql-Modules