© 2025-2026 PySpect
First version without a known vulnerability: 0.315.7
Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification
Fixed in: 0.315.7
Strawberry GraphQL has a Circular Fragment Reference DOS
Fixed in: 0.315.7
Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs
Fixed in: 0.315.4
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions
Fixed in: 0.312.3
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol
Fixed in: 0.312.3
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Fixed in: 0.257.0
Cross-Site Request Forgery (CSRF) in strawberry-graphql
Fixed in: 0.243.0, 37265b230e511480a9ceace492f9f6a484be1387