ZeroHour

CVE-2026-59288

moderate

Cross-site information leak via crafted GraphiQL URLs in VMware Spring for GraphQL

CVSS 3.1
7.4 high
EPSS
<1%p19
Published
()
Modified
AI analysis

The GraphiQL page bundled with Spring for GraphQL sends requests to the application's GraphQL endpoint, and the flaw lets an attacker-crafted URL cause the victim's browser to issue those requests and leak confidential information, potentially data the victim is authorized to see, to the attacker's website. Exploitation requires user interaction: the victim must open an attacker-supplied link pointing at the application's GraphiQL page. The attacker gains read access to sensitive GraphQL API data (high confidentiality impact only, with no integrity or availability impact per the scope-changed CVSS vector). Any application built on the affected Spring for GraphQL releases that exposes the bundled GraphiQL page is affected, including internal-only applications, since the victim only needs network access to the endpoint. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low (0.3%), so no exploitation is currently known.

What to do: Upgrade Spring for GraphQL to a release newer than your branch's affected range (later than 2.0.4, 1.4.6, 1.3.9, or 1.0.7) per the VMware/Spring advisory. As an interim mitigation, disable or restrict access to the bundled GraphiQL page in production and be cautious with untrusted links that resolve to /graphiql endpoints. Audit whether your GraphQL endpoint is internet-exposed and whether it returns sensitive data to authenticated user sessions.

Affected
VMware Spring for GraphQL2.0.0 - 2.0.4
VMware Spring for GraphQL1.4.0 - 1.4.6
VMware Spring for GraphQL1.1.0 - 1.3.9
VMware Spring for GraphQL1.0.0 - 1.0.7
Estimated exposure
moderateon the order of 10,000-100,000 deployed applications/endpoints with the bundled GraphiQL page enabled — Spring for GraphQL is the standard GraphQL server stack for the very large Spring Boot ecosystem, but GraphQL adoption is a minority of API deployments and public internet scans of exposed /graphiql endpoints number in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

Vendors
vmware
Products
spring for graphql
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.