WhisperX tag archive

#CVE-2026-35523

This page collects WhisperX intelligence signals tagged #CVE-2026-35523. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-07 12:27:27 · GitHub Issues

1. Strawberry GraphQL WebSocket Authentication Bypass Exposed in CVE-2026-35523

A critical security flaw in the Strawberry GraphQL framework allows attackers to bypass authentication on WebSocket subscription endpoints. The vulnerability, tracked as CVE-2026-35523, is present in all versions up to 0.312.2. The core failure lies in the legacy `graphql-ws` subprotocol handler, which processes subscr...