CVE-2026-59289
- EPSS 0.16%
- Veröffentlicht 27.08.2026 17:57:47
- Zuletzt bearbeitet 02.09.2026 17:17:48
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust applica...
CVE-2026-59288
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:46
- Zuletzt bearbeitet 01.09.2026 16:17:06
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for...
CVE-2026-59287
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:45
- Zuletzt bearbeitet 02.09.2026 17:17:47
Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9
CVE-2026-59286
- EPSS 0.11%
- Veröffentlicht 27.08.2026 17:57:44
- Zuletzt bearbeitet 02.09.2026 18:20:35
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQ...
CVE-2026-59285
- EPSS 0.44%
- Veröffentlicht 27.08.2026 17:57:43
- Zuletzt bearbeitet 02.09.2026 19:17:25
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4
CVE-2026-41856
- EPSS 0.35%
- Veröffentlicht 11.06.2026 05:05:00
- Zuletzt bearbeitet 23.07.2026 09:10:00
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditio...
CVE-2026-41700
- EPSS 0.19%
- Veröffentlicht 11.06.2026 05:04:47
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL...
CVE-2026-41699
- EPSS 0.43%
- Veröffentlicht 11.06.2026 05:04:43
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Con...
CVE-2023-34047
- EPSS 0.36%
- Veröffentlicht 20.09.2023 10:15:14
- Zuletzt bearbeitet 21.11.2024 08:06:28
A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoade...