Denial of Service Vulnerability in Spring for GraphQL by VMware
CVE-2026-59289
7.5HIGH
What is CVE-2026-59289?
The Spring for GraphQL framework contains a vulnerability in its Data pagination support that allows an attacker to construct a malicious query targeting a Connection field. By doing so, the attacker can send crafted inputs that may overwhelm application memory or cause extensive strain on the underlying datastore, ultimately leading to a Denial of Service. This behavior affects specific versions of Spring for GraphQL, which may impact applications relying on these versions.
Affected Version(s)
Spring for GraphQL 2.0.0 <= 2.0.4
Spring for GraphQL 1.4.0 <= 1.4.6
Spring for GraphQL 1.2.0 <= 1.3.9
