Description
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.1.0 - 1.3.9
Spring for GraphQL 1.0.0 - 1.0.7
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs in the GraphiQL interface bundled with Spring for GraphQL. A crafted URL can cause a victim’s browser to send GraphQL requests that may expose confidential data to an attacker’s domain. This results in information disclosure and compromises confidentiality of data accessed by the GraphQL endpoints.

Affected Systems

The issue affects Spring for GraphQL. Supported products are: Spring:Spring for GraphQL. Affected releases include 2.0.0‑2.0.4, 1.4.0‑1.4.6, 1.1.0‑1.3.9, and 1.0.0‑1.0.7. If your application uses any of these versions, it is vulnerable.

Risk and Exploitability

The CVSS score is not provided in the public data, and that the EPSS score is not available, so the published exploitation probability cannot be quantified. The vulnerability is listed as not in the CISA KEV catalog, indicating no confirmed widespread exploitation cases yet. Nevertheless, the attack vector is inferred to be a direct example of an attacker distributing a malicious link that a victim may click, leading to browser‑initiated requests to internal GraphQL endpoints. Because the leak depends on the victim opening a link, the risk is limited to users who are exposed to the crafted URL, but the potential loss of confidential information is significant.

Generated by OpenCVE AI on August 28, 2026 at 06:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spring for GraphQL to a non‑affected version (for example, 2.0.5 or later).
  • Disable or remove the GraphiQL page in production environments, especially when exposed to public traffic.
  • If immediate removal is not feasible, restrict GraphiQL access behind authentication or limit its exposure to trusted users.

Generated by OpenCVE AI on August 28, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring For Graphql
Vendors & Products Spring
Spring spring For Graphql

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Title Spring for GraphQL Information Exposure in GraphiQL support
References

Subscriptions

Spring Spring For Graphql
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T17:57:46.990Z

Reserved: 2026-07-04T18:13:26.298Z

Link: CVE-2026-59288

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:55.013

Modified: 2026-08-27T20:17:55.013

Link: CVE-2026-59288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor