Spring for GraphQL

5 known vulnerabilities in Spring for GraphQL, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-59289 CVSS 7.5 high Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to…
  • CVE-2026-59288 CVSS 7.4 high The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a…
  • CVE-2026-59287 CVSS 5.9 medium Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL…
  • CVE-2026-59286 CVSS 8.1 high The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An…
  • CVE-2026-59285 CVSS 8.1 high Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL…