Description
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the context of the requests is mixed up in the service when the context is injected via @ExecutionContext(). ExecutionContext is often used to pass authentication tokens from incoming requests to services loading data from backend APIs. This vulnerability is fixed in 2.4.1 and 3.1.1.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/graphql-hive/graphql-modules/security/advisories/GHSA-53wg-r69p-v3r7
Issue Tracking x_refsource_misc
https://github.com/graphql-hive/graphql-modules/issues/2613
Issue Tracking x_refsource_misc
https://github.com/graphql-hive/graphql-modules/pull/2521
Release Notes x_refsource_misc
https://github.com/graphql-hive/graphql-modules/releases/tag/release-1768575025568
Scores
CVSS v4
8.7
EPSS
0.0046
EPSS Percentile
36.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-362
Status
published
Products (3)
graphql-hive/graphql-modules
>= 2.2.1, < 2.4.1
graphql-hive/graphql-modules
>= 3.0.0, < 3.1.1
npm/graphql-modules
2.2.1 - 2.4.1npm
Published
Jan 16, 2026
Tracked Since
Feb 18, 2026