Cross-Site WebSocket Hijacking Vulnerability in Spring for GraphQL
CVE-2026-41700

8.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-41700?

Applications using Spring for GraphQL that have the WebSocket transport enabled are susceptible to Cross-Site WebSocket Hijacking. This vulnerability allows attackers to exploit the authenticated sessions of users by tricking them into visiting malicious pages. When successful, the attackers can perform unauthorized GraphQL operations using the victim's credentials, potentially leading to data compromise and unauthorized actions within the application.

Affected Version(s)

Spring for GraphQL 2.0.0 < 2.0.3.1

Spring for GraphQL 1.4.0 < 1.4.5.1

Spring for GraphQL 1.3.0 < 1.3.9

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.