Cross-Site WebSocket Hijacking in Spring for GraphQL
CVE-2026-41700

8.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-41700?

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials.

Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

Affected Version(s)

Spring for GraphQL 2.0.0 < 2.0.4

Spring for GraphQL 1.4.0 < 1.4.6

Spring for GraphQL 1.3.0 < 1.3.9

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.