strawberry-graphql vulnerabilities
CVEs whose affected-version data names the strawberry-graphql package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-47706Medium· 5.3Strawberry GraphQL has a Circular Fragment Reference DOS
Strawberry GraphQL has a Circular Fragment Reference DOS
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.30%via OSV
CVE-2026-47707Medium· 5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.47%via OSV
CVE-2026-45739Low· 3.1Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.22%via OSV
CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.38%via OSV