PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107728 strawberry-graphql CVE debrief

CVE-2026-107728 Strawberry GraphQL Synchronous permission checks treat awaitable authorization result as truthy. The vulnerability affects synchronous field resolvers under both execute_sync() and execute() in versions from 0.217.0 to 0.326.1. Defenders should verify exposure, assess permission configurations, and upgrade to version 0.326.1 if necessary. This high-severity issue can allow unauthorized access to protected GraphQL resolvers. The fix involves upgrading to strawberry-graphql version 0.326.1 or later. Official sources include the CVE Program and NIST NVD.

Vendor
strawberry-graphql
Product
strawberry
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for GraphQL APIs using strawberry-graphql, particularly those with custom permission configurations, should assess exposure and prioritize upgrading to version 0.326.1.

Why it matters

CVE-2026-107728 is a high-severity vulnerability in strawberry-graphql that can allow unauthorized access to protected GraphQL resolvers. Defenders should verify exposure, assess permission configurations, and upgrade to version 0.326.1 if necessary.

  • Potential unauthorized access to protected GraphQL resolvers
  • Need to verify permission configurations for synchronous field resolvers
  • Possible exposure in GraphQL APIs using affected strawberry-graphql versions
  • Requires upgrading to strawberry-graphql version 0.326.1 for fix

Technical summary

Strawberry GraphQL library for creating GraphQL APIs has a vulnerability in versions from 0.217.0 to 0.326.1. Synchronous permission checks can treat an awaitable authorization result as truthy, allowing protected resolvers to run even when the result would resolve to false. This affects synchronous field resolvers under both execute_sync() and execute(). Permissions declared with async def has_permission() and synchronous permissions returning a boolean are not affected.

Defensive priority

Defenders should prioritize verifying exposure in GraphQL APIs using strawberry-graphql versions between 0.217.0 and 0.326.1, assessing permission configurations and upgrading to 0.326.1 if necessary.

Recommended defensive actions

  • Verify if GraphQL APIs using strawberry-graphql are exposed to unauthorized access due to this vulnerability.
  • Assess permission configurations for synchronous field resolvers.
  • Upgrade strawberry-graphql to version 0.326.1 or later.
  • Review and update permission checks for custom permissions.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and source item provide details on the vulnerability in strawberry-graphql, affecting versions from 0.217.0 to 0.326.1. Official sources include the CVE Program and NIST NVD. The issue is fixed in version 0.326.1. Defenders should verify exposure and assess permission configurations for synchronous field resolvers. The vulnerability allows protected resolvers to run even when the result would resolve to false. Permissions declared with async def has_permission() and synchronous permissions returning a boolean are not A

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107728 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107728

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107728 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107728

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107728.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-pfvf-fwfp-25mp

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/strawberry-graphql/strawberry/pull/4605

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/strawberry-graphql/strawberry/commit/2ebb79796c0e5ebb43cae1abd2b5a21363b1c00e

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/strawberry-graphql/strawberry/releases/tag/0.326.1

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.