strawberry-graphql has 4 CVEs on record between 2025 and 2026. The median CVSS is 4.5 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
Products
- strawberry-graphql 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-47707Medium· 5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification29CVE-2026-47706Medium· 5.3Strawberry GraphQL has a Circular Fragment Reference DOS29CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution20CVE-2026-45739Low· 3.1Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs17
strawberry-graphql vulnerabilities
CVEs affecting strawberry-graphql, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-47706Medium· 5.3Strawberry GraphQL has a Circular Fragment Reference DOS
Strawberry GraphQL has a Circular Fragment Reference DOS
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.30%via OSV
CVE-2026-47707Medium· 5.3Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.47%via OSV
CVE-2026-45739Low· 3.1Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.22%via OSV
CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
▾ Sunlitstrawberry-graphql · strawberry-graphqlEPSS 0.38%via OSV