- Community aggregator
- Country: United States
CVE-2026-103921: CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws
CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws Vulnerability ID: CVE-2026-103921 CVSS Score: 7.4 Published: 2026-10-05 A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for…