PatchSiren cyber security CVE debrief
CVE-2026-107728 strawberry-graphql CVE debrief
CVE-2026-107728 Strawberry GraphQL Synchronous permission checks treat awaitable authorization result as truthy. The vulnerability affects synchronous field resolvers under both execute_sync() and execute() in versions from 0.217.0 to 0.326.1. Defenders should verify exposure, assess permission configurations, and upgrade to version 0.326.1 if necessary. This high-severity issue can allow unauthorized access to protected GraphQL resolvers. The fix involves upgrading to strawberry-graphql version 0.326.1 or later. Official sources include the CVE Program and NIST NVD.
- Vendor
- strawberry-graphql
- Product
- strawberry
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for GraphQL APIs using strawberry-graphql, particularly those with custom permission configurations, should assess exposure and prioritize upgrading to version 0.326.1.
Why it matters
CVE-2026-107728 is a high-severity vulnerability in strawberry-graphql that can allow unauthorized access to protected GraphQL resolvers. Defenders should verify exposure, assess permission configurations, and upgrade to version 0.326.1 if necessary.
- Potential unauthorized access to protected GraphQL resolvers
- Need to verify permission configurations for synchronous field resolvers
- Possible exposure in GraphQL APIs using affected strawberry-graphql versions
- Requires upgrading to strawberry-graphql version 0.326.1 for fix
Technical summary
Strawberry GraphQL library for creating GraphQL APIs has a vulnerability in versions from 0.217.0 to 0.326.1. Synchronous permission checks can treat an awaitable authorization result as truthy, allowing protected resolvers to run even when the result would resolve to false. This affects synchronous field resolvers under both execute_sync() and execute(). Permissions declared with async def has_permission() and synchronous permissions returning a boolean are not affected.
Defensive priority
Defenders should prioritize verifying exposure in GraphQL APIs using strawberry-graphql versions between 0.217.0 and 0.326.1, assessing permission configurations and upgrading to 0.326.1 if necessary.
Recommended defensive actions
- Verify if GraphQL APIs using strawberry-graphql are exposed to unauthorized access due to this vulnerability.
- Assess permission configurations for synchronous field resolvers.
- Upgrade strawberry-graphql to version 0.326.1 or later.
- Review and update permission checks for custom permissions.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details on the vulnerability in strawberry-graphql, affecting versions from 0.217.0 to 0.326.1. Official sources include the CVE Program and NIST NVD. The issue is fixed in version 0.326.1. Defenders should verify exposure and assess permission configurations for synchronous field resolvers. The vulnerability allows protected resolvers to run even when the result would resolve to false. Permissions declared with async def has_permission() and synchronous permissions returning a boolean are not A
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107728 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107728
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107728 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107728
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107728.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-pfvf-fwfp-25mp
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/strawberry-graphql/strawberry/pull/4605
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/strawberry-graphql/strawberry/commit/2ebb79796c0e5ebb43cae1abd2b5a21363b1c00e
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/strawberry-graphql/strawberry/releases/tag/0.326.1
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.