216.73.216.233

CVE-2026-23735

· Published 16/01/2026 20:15 · Modified 16/01/2026 20:15

Labels: CVE-2026-23735 2026-01-16CVE-2026-23735CWE-362[email protected]

Essential information

Published
16/01/2026 20:15
Modified
16/01/2026 20:15
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the service when the context is injected via @ExecutionContext(). ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This vulnerability is fixed in 2.4.1 and 3.1.1.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
graphql modules / graphql modules cpe:2.3:a:graphql_modules:graphql_modules:2.2.1-2.4.0:*:*:*:*:*:*:*
graphql modules / graphql modules cpe:2.3:a:graphql_modules:graphql_modules:3.1.1:*:*:*:*:*:*:*

References