Cross-Site WebSocket Hijacking Vulnerability in Spring for GraphQL
CVE-2026-41700
8.1HIGH
What is CVE-2026-41700?
Applications using Spring for GraphQL that have the WebSocket transport enabled are susceptible to Cross-Site WebSocket Hijacking. This vulnerability allows attackers to exploit the authenticated sessions of users by tricking them into visiting malicious pages. When successful, the attackers can perform unauthorized GraphQL operations using the victim's credentials, potentially leading to data compromise and unauthorized actions within the application.
Affected Version(s)
Spring for GraphQL 2.0.0 < 2.0.3.1
Spring for GraphQL 1.4.0 < 1.4.5.1
Spring for GraphQL 1.3.0 < 1.3.9
