Vulnerability record · CVE-2026-45739 · published 4 June 2026
CVE-2026-45739: Strawberry graphql information exposure vulnerability
Strawberry · Strawberry Graphql
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue.
Description
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/strawberry-graphql/strawberry/commit/9315ef80a621ae50ca0bc5c82f560ca4ee7e47a9 | Patch |
| https://github.com/strawberry-graphql/strawberry/issues/4398 | Issue Tracking |
| https://github.com/strawberry-graphql/strawberry/pull/2842 | Issue TrackingPatch |
| https://github.com/strawberry-graphql/strawberry/releases/tag/0.315.4 | ProductRelease Notes |
| https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-x97m-qp5c-w9xj | MitigationVendor Advisory |
Track CVE-2026-45739 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-45739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.