Skip to main content

Vendor/product archive

vmware / spring_for_graphql CVEs

Beta · best-effort

4 CVEs tagged to vmware / spring_for_graphql0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-41856

Published Jun 11, 2026

The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if s…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41700

Published Jun 11, 2026

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiti…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41699

Published Jun 11, 2026

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34047

Published Sep 20, 2023

A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a dif…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1