Denial of Service Vulnerability in Spring for GraphQL by Spring
CVE-2026-59287

5.9MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59287?

Spring for GraphQL is susceptible to Denial of Service attacks when the WebSocket client utilizes the keepAlive feature. This vulnerability affects specific versions of the product, allowing malicious actors to disrupt services by exploiting the interaction between WebSocket connections and keepAlive settings. Users of Spring for GraphQL should assess their current versions and implement mitigative measures to secure their applications against potential exploitations.

Affected Version(s)

Spring for GraphQL 2.0.0 <= 2.0.4

Spring for GraphQL 1.4.0 <= 1.4.6

Spring for GraphQL 1.3.0 <= 1.3.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.