Script Injection Vulnerability in Spring for GraphQL by VMware
CVE-2026-59286

8.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59286?

The GraphiQL page packaged with Spring for GraphQL is vulnerable due to its reliance on public CDN-hosted JavaScript libraries without implementing Subresource Integrity checks. This oversight allows attackers to inject harmful scripts that can execute arbitrary code on the browsers interacting with the GraphiQL page. The affected versions span from Spring for GraphQL 1.0.0 to 2.0.4, posing significant security risks for users.

Affected Version(s)

Spring for GraphQL 2.0.0 <= 2.0.4

Spring for GraphQL 1.4.0 <= 1.4.6

Spring for GraphQL 1.1.0 <= 1.3.9

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.