PT-2026-3319 · Unknown · Graphql-Modules

Duckthom

·

Published

2026-01-16

·

Updated

2026-01-17

·

CVE-2026-23735

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GraphQL Modules versions 2.2.1 through 2.4.0 GraphQL Modules versions 3.1.1
Description GraphQL Modules has an issue where, when two or more parallel requests trigger the same service, the context of the requests can become mixed up within the service when the context is injected via @ExecutionContext(). The ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This can lead to unauthorized access or data breaches. An estimated number of potentially affected devices worldwide is not available. There are no reports of real-world incidents where this issue was exploited. The vulnerability occurs when using the @ExecutionContext() decorator. The context variable can be affected when multiple requests are processed concurrently.
Recommendations Update to GraphQL Modules version 2.4.1 or later. Update to GraphQL Modules version 3.1.1 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2026-23735
GHSA-53WG-R69P-V3R7

Affected Products

Graphql-Modules