5.9
CVE-2026-59287
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:45
- Zuletzt bearbeitet 02.09.2026 17:17:47
- Erkennungen
Spring for GraphQL WebSocket Client Denial of Service
Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring For Graphql Version >= 1.3.0 < 1.3.10
VMware ≫ Spring For Graphql Version >= 1.4.0 < 1.4.7
VMware ≫ Spring For Graphql Version >= 2.0.0 < 2.0.4.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.044 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| CISA-ADP | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://spring.io/security/cve-2026-59287