Listen to this Post
Strawberry GraphQL legacy graphql-ws subscription handler retains task bookkeeping.
Completed one-shot subscriptions leave state in self.tasks.
The natural completion path skips calling cleanup_operation().
Operation entries remain active until explicitly stopped or reuses the ID.
Configuring max_subscriptions_per_connection causes accounting mismatches.
Distinct operation IDs exhaust connection slots rapidly.
Subsequent legitimate subscriptions receive subscription limit reached errors.
This creates a conditional connection-level availability vulnerability.
It requires persistent WebSocket connections and legacy protocol usage.
The vulnerability affects versions from 0.312.3 up to 0.327.0.
Modern graphql-transport-ws protocol remains entirely unaffected.
Default installations without per-connection limits are not exposed.
The bookkeeping leak stems from missing cleanup hooks on exhaustion.
Result sources naturally exhaust and send complete messages.
The handler counts completed operations in len(self.tasks).
Clients can fill slots with finished one-shot operations.
New operations are rejected despite zero active subscriptions.
Resource accounting becomes incorrect across persistent connections.
Memory or slot exhaustion can affect specific long-lived sessions.
The issue was reported and analyzed in GitHub security advisory.
Maintainers confirmed reproduction against version 0.327.0.
Fixes ensure operations release slots upon completion or failure.
Late stop calls for completed operations become safe no-ops.
The official patch was released in version 0.327.2.
Users must update their packages to mitigate slot locking.
Developers should audit protocol configurations across deployments.
Proper slot release logic restores normal resource management.
DailyCVE Form:
Platform: Strawberry GraphQL
Version: 0.312.3 to 0.327.0
Vulnerability: Task Slot Retention
Severity: Low Risk
Date: September 2, 2026
Prediction: Patched in 0.327.2
What Undercode Say:
Showing bash commands and codes related to the blog
python -m pip install "strawberry-graphql[bash]==0.324.4" daphne
python -c "import sys, importlib.metadata as m; print(sys.version); print('strawberry-graphql:', m.version('strawberry-graphql'))"
import asyncio from channels.testing import WebsocketCommunicator from strawberry.channels.handlers.ws_handler import GraphQLWSConsumer from strawberry.schema import Schema from strawberry.subscriptions import GRAPHQL_WS_PROTOCOL @strawberry.type class Subscription: @strawberry.subscription async def one_shot(self) -> str: yield "marker"
Exploit: (Educational Purposes!)
The reproduction uses an in-memory Channels WebSocket fixture with the legacy graphql-ws subprotocol. By sending three distinct one-shot subscription operations that naturally complete, the client fills the max_subscriptions_per_connection limit of 2. When the third operation starts, it gets rejected with a “Subscription limit reached” error message even though previous operations have already finished execution.
Protection: from this CVE
Upgrade strawberry-graphql to version 0.327.2 or newer, which ensures operations release their slots upon natural completion or failure.
Impact:
Connection-level availability issues and incorrect resource accounting on persistent WebSocket connections using legacy subscriptions.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

