Vmware Spring For Graphql — known CVE vulnerabilities
Every CVE whose affected-product data names Vmware Spring For Graphql, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (9)
CVE-2026-59285 — CVSS 8.1 (high): Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL…
CVE-2026-59286 — CVSS 8.1 (high): The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An…
CVE-2026-41700 — CVSS 8.1 (high): Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can…
CVE-2026-41699 — CVSS 8.1 (high): Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a…
CVE-2026-59289 — CVSS 7.5 (high): Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the…
CVE-2026-41856 — CVSS 7.5 (high): The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within…
CVE-2026-59288 — CVSS 7.4 (high): The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a…
CVE-2026-59287 — CVSS 5.9 (medium): Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL…
CVE-2023-34047 — CVSS 3.1 (low): A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values…