Description
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.1.0 - 1.3.9
Spring for GraphQL 1.0.0 - 1.0.7
Published: 2026-08-27
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side code execution via unverified external JavaScript
Action: Immediate Patch
AI Analysis

Impact

Spring for GraphQL incorporates the GraphiQL web interface with client‑side JavaScript resources served from a public CDN without Subresource Integrity checks. An attacker who can modify the CDN content can inject malicious code that will run in the victim’s browser whenever the GraphiQL page is accessed, enabling arbitrary script execution, data theft, or further lateral movement.

Affected Systems

Spring for GraphQL versions 2.0.0 through 2.0.4, 1.4.0 through 1.4.6, 1.1.0 through 1.3.9, and 1.0.0 through 1.0.7 are affected. Deployments that expose the GraphiQL interface to users are therefore vulnerable.

Risk and Exploitability

The CVSS score of 8.1 and the EPSS score of < 1% indicate a high severity but a low exploitation probability for this vulnerability. The vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation at this time. Nevertheless, the purely client‑side attack vector potentially allows any user who visits the interface to be compromised, underscoring high risk for exposed environments.

Generated by OpenCVE AI on September 1, 2026 at 01:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a Spring for GraphQL version that addresses this issue, if available
  • If upgrading is not feasible, restrict access to the GraphiQL endpoint (e.g., disable it or protect it behind authentication and network segmentation)
  • Host the GraphiQL JavaScript libraries locally and apply Subresource Integrity to the local copies to eliminate dependency on an external CDN.

Generated by OpenCVE AI on September 1, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 03 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 31 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring For Graphql
Weaknesses CWE-494
CPEs cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware spring For Graphql
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 28 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring For Graphql
Vendors & Products Spring
Spring spring For Graphql

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Title Spring for GraphQL loads Untrusted Resources in GraphiQL support
References

Subscriptions

Spring Spring For Graphql
Vmware Spring For Graphql
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-09-02T17:35:48.563Z

Reserved: 2026-07-04T18:13:26.297Z

Link: CVE-2026-59286

cve-icon Vulnrichment

Updated: 2026-09-02T17:27:02.815Z

cve-icon NVD

Status : Modified

Published: 2026-08-27T20:17:54.797

Modified: 2026-09-02T18:20:35.237

Link: CVE-2026-59286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T01:30:03Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check