CVE-2026-107727
Received Received - Intake

Heap Exhaustion in Strawberry GraphQL Subscriptions

Vulnerability report for CVE-2026-107727, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Strawberry GraphQL is a library for creating GraphQL APIs. From 0.312.3 until 0.327.2, the legacy graphql-ws subscription handler in strawberry/subscriptions/protocols/graphql_ws/handlers.py does not remove naturally completed operations from self.tasks and self.subscriptions. When max_subscriptions_per_connection is configured, a client on a persistent WebSocket connection can use distinct operation IDs for one-shot subscriptions to fill the connection's configured slots even after those subscriptions send complete, causing later legitimate operations on that connection to be rejected with Subscription limit reached. The modern graphql-transport-ws protocol and deployments without the configured per-connection cap are not affected. This issue is fixed in version 0.327.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
strawberry-graphql strawberry >= 0.312.3, < 0.327.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Strawberry GraphQL versions 0.312.3 to 0.327.2 have a flaw in the legacy graphql-ws subscription handler. It fails to remove completed operations from internal tracking lists. This allows attackers to fill subscription slots on a WebSocket connection by repeatedly sending one-shot subscriptions with different IDs, even after they complete. Legitimate operations are then rejected due to the perceived subscription limit.

Detection Guidance

To detect this vulnerability, check if your Strawberry GraphQL version is between 0.312.3 and 0.327.1. Run: pip show strawberry-graphql. If the version falls in this range, the system is vulnerable. No specific commands are provided for runtime detection beyond version checks.

Impact Analysis

If you use Strawberry GraphQL with WebSocket subscriptions and have max_subscriptions_per_connection enabled, an attacker could disrupt your service by blocking legitimate users from creating new subscriptions. This could lead to denial-of-service conditions for users trying to access real-time features.

Compliance Impact

This vulnerability could indirectly impact compliance by causing service disruptions that affect data availability. For GDPR, availability is a key principle. For HIPAA, service interruptions might affect access to protected health information. However, the vulnerability itself does not directly violate these regulations.

Mitigation Strategies

Upgrade Strawberry GraphQL to version 0.327.2 or later to fix the issue with subscription task cleanup.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107727. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart