Answer in brief
CVE-2026-107728 records a High severity (CVSS 7.5) vulnerability in Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy. The current sources do not mark it as known exploited. The current feed maps strawberry-graphql/strawberry (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps strawberry-graphql/strawberry (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| strawberry-graphql/strawberrygeneric | >=0.217.0 <0.326.1 | 0.326.1 |
Published upstream
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 8, 2026
Strawberry GraphQL is a library for creating GraphQL APIs. From 0.217.0 until 0.326.1, PermissionExtension.resolve() on a synchronous field resolver evaluates the result of has_permission() for truthiness. When a custom permission declares has_permission() as a normal function but returns an awaitable, supports_sync does not classify it as asynchronous, the awaitable is not awaited, and its inherently truthy object value permits the protected resolver to run even when the result would resolve to false. This affects synchronous field resolvers under both execute_sync() and execute(); permissions declared with async def has_permission() and synchronous permissions returning a boolean are not affected. This issue is fixed in version 0.326.1.
Quoted source text, attributed separately from HOL analysis.