Script Injection Vulnerability in Spring for GraphQL by VMware
CVE-2026-59286
8.1HIGH
What is CVE-2026-59286?
The GraphiQL page packaged with Spring for GraphQL is vulnerable due to its reliance on public CDN-hosted JavaScript libraries without implementing Subresource Integrity checks. This oversight allows attackers to inject harmful scripts that can execute arbitrary code on the browsers interacting with the GraphiQL page. The affected versions span from Spring for GraphQL 1.0.0 to 2.0.4, posing significant security risks for users.
Affected Version(s)
Spring for GraphQL 2.0.0 <= 2.0.4
Spring for GraphQL 1.4.0 <= 1.4.6
Spring for GraphQL 1.1.0 <= 1.3.9
