Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x97m-qp5c-w9xj | Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs |
Fri, 05 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strawberry strawberry Graphql
|
|
| CPEs | cpe:2.3:a:strawberry:strawberry_graphql:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Strawberry strawberry Graphql
|
Fri, 05 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strawberry
Strawberry strawberry |
|
| Vendors & Products |
Strawberry
Strawberry strawberry |
Thu, 04 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser URL query string. If a user entered a sensitive header, such as `Authorization: Bearer <token>`, the value could become visible in browser history, copied links, and server/proxy/CDN access logs after a page reload or shared request. Version 0.315.4 patches the issue. | |
| Title | Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs | |
| Weaknesses | CWE-200 CWE-201 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-04T14:36:06.010Z
Reserved: 2026-05-13T06:54:34.219Z
Link: CVE-2026-45739
Updated: 2026-06-04T14:35:53.011Z
Status : Analyzed
Published: 2026-06-04T15:16:54.457
Modified: 2026-06-05T18:43:20.977
Link: CVE-2026-45739
No data.
OpenCVE Enrichment
Updated: 2026-06-05T07:45:35Z
Github GHSA