Denial of Service Vulnerability in Spring for GraphQL by Spring
CVE-2026-59287
5.9MEDIUM
What is CVE-2026-59287?
Spring for GraphQL is susceptible to Denial of Service attacks when the WebSocket client utilizes the keepAlive feature. This vulnerability affects specific versions of the product, allowing malicious actors to disrupt services by exploiting the interaction between WebSocket connections and keepAlive settings. Users of Spring for GraphQL should assess their current versions and implement mitigative measures to secure their applications against potential exploitations.
Affected Version(s)
Spring for GraphQL 2.0.0 <= 2.0.4
Spring for GraphQL 1.4.0 <= 1.4.6
Spring for GraphQL 1.3.0 <= 1.3.9
