Unsafe Deserialization in Spring for GraphQL Affects Specific Versions
CVE-2026-59285

8.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59285?

Spring for GraphQL applications are at risk of Unsafe Deserialization vulnerabilities when handling paginated GraphQL queries. This flaw can lead to potentially harmful behaviors if exploited, as it allows attackers to manipulate data types and inject malicious objects through the deserialization process. Developers should ensure proper input validation and consider upgrading to secure versions to mitigate this risk.

Affected Version(s)

Spring for GraphQL 2.0.0 <= 2.0.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.