Impact
Spring for GraphQL performs deserialization of pagination information without proper validation, allowing an attacker to supply crafted data that can instantiate unintended classes. The flaw is classified as CWE-502 and can enable the execution of arbitrary code, exposing the application to complete compromise of confidentiality, integrity, and availability.
Affected Systems
The vulnerability impacts Spring for GraphQL versions 2.0.0 through 2.0.4. Deployments running any of these releases are at risk; no other versions are listed as affected in the advisory.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, meaning no widespread exploitation is known yet. The most likely attack vector is remote, exploiting the GraphQL API’s pagination parameters, which require an attacker to inject malicious payloads into a paginated query.
OpenCVE Enrichment