CVE-2026-45739
📛 CVE Title
(no title)
Description
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- low
- CVSS score
- 3.1 / 10
- CVSS vector
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N- Effective score
- 3.1 / 10 LOW source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45739
NVD / KEV / EPSS data refreshed 2026-05-25 00:13 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-34270 - Assigner
- GitHub_M
- Published
- Jun 4, 2026, 2:09:03 PM
- Updated
- Jun 4, 2026, 2:36:06 PM
- EUVD base score (CVSS 3.1)
-
3.1 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N - EUVD-reported EPSS
- 0.2200
- Vendors
- strawberry-graphql
- Products
-
strawberry (0.288.4, < 0.315.4)
- Aliases
-
GHSA-x97m-qp5c-w9xj
ENISA description: Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue.
EUVD references (5)
- https://github.com/strawberry-graphql/strawberry/security/advisories/GHSA-x97m-qp5c-w9xj
- https://github.com/strawberry-graphql/strawberry/issues/4398
- https://github.com/strawberry-graphql/strawberry/pull/2842
- https://github.com/strawberry-graphql/strawberry/commit/9315ef80a621ae50ca0bc5c82f560ca4ee7e47a9
- https://github.com/strawberry-graphql/strawberry/releases/tag/0.315.4
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (2)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://nvd.nist.gov/vuln/detail/CVE-2026-45739 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45739 tenable:www.cve.org
Remediations (10)
-
web:blog.qualys.com
With Qualys Policy Audit's out-of-the-box mitigation or Compensatory Controls, which reduce the risk of a vulnerability being exploited because the remediation ( fix / patch ) cannot be done immediately, these security controls are not recommended by any industry standards, such as CIS and DISA-STIG.
2026-05-26 03:08 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-05-26 03:08 UTC -
web:pureinfotech.com
Windows 11 builds 26200.8246 and 26100.8246 arrive with various changes and fixes as part of the April 2026 Patch Tuesday update.
2026-05-26 03:08 UTC -
web:www.crowdstrike.com
Microsoft's April 2026 Patch Tuesday addresses 164 CVEs , featuring 8 Critical vulnerabilities, one exploited zero-day, and one disclosed zero-day.
2026-05-26 03:08 UTC -
web:www.notebookcheck.net
Microsoft's Windows 11 KB5083769 April 2026 update causes critical boot failures, pixelated BSODs, and BitLocker recovery loops on Windows 11 24H2 and 25H2 PCs.
2026-05-26 03:08 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-26 03:08 UTC -
web:www.prajwaldesai.com
Microsoft's KB5083769 update for Windows 11 fixes "Reset this PC" errors, boosts SMB compression reliability over QUIC, and enhances phishing defenses for .rdp files.
2026-05-26 03:08 UTC -
web:www.thurrott.com
The April 2026 Patch Tuesday updates for Windows 11 versions 25H2 and 24H2 bring various accessibility improvements, support for refresh rates higher than 1000Hz, and more.
2026-05-26 03:08 UTC -
web:www.windowslatest.com
Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.
2026-05-26 03:08 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-26 03:08 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.