Description
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.1.0 - 1.3.9
Spring for GraphQL 1.0.0 - 1.0.7
Published: 2026-08-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability occurs in the GraphiQL interface bundled with Spring for GraphQL. A crafted URL can cause a victim’s browser to send GraphQL requests that may expose confidential data to an attacker’s domain. This results in information disclosure and compromises the confidentiality of data accessed by the GraphQL endpoints.

Affected Systems

The issue affects Spring for GraphQL. Supported products are: Spring:Spring for GraphQL. Affected releases include 2.0.0‑2.0.4, 1.4.0‑1.4.6, 1.1.0‑1.3.9, and 1.0.0‑1.0.7. If your application uses any of these versions, it is vulnerable.

Risk and Exploitability

The CVSS score is 7.5 and the EPSS score is less than 1%, indicating a low yet non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The attack vector is likely an attacker issuing a malicious URL that a victim clicks, causing the victim’s browser to send GraphQL requests that could leak confidential data. Since the leak depends on the victim accessing the crafted URL, the risk is limited to those exposed to the link, but the potential loss of confidential information remains significant.

Generated by OpenCVE AI on September 2, 2026 at 06:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spring for GraphQL to a non‑affected version (for example, 2.0.5 or later).
  • Disable or remove the GraphiQL page in production environments, especially when exposed to public traffic.
  • If immediate removal is not feasible, restrict GraphiQL access behind authentication or limit its exposure to trusted users.

Generated by OpenCVE AI on September 2, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 31 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware spring For Graphql
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware spring For Graphql
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Fri, 28 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring For Graphql
Vendors & Products Spring
Spring spring For Graphql

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Title Spring for GraphQL Information Exposure in GraphiQL support
References

Subscriptions

Spring Spring For Graphql
Vmware Spring For Graphql
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-09-01T15:36:35.910Z

Reserved: 2026-07-04T18:13:26.298Z

Link: CVE-2026-59288

cve-icon Vulnrichment

Updated: 2026-09-01T15:36:09.624Z

cve-icon NVD

Status : Modified

Published: 2026-08-27T20:17:55.013

Modified: 2026-09-01T16:17:06.887

Link: CVE-2026-59288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T06:30:07Z

Weaknesses