CVE-2026-59288
moderateCross-site information leak via crafted GraphiQL URLs in VMware Spring for GraphQL
The GraphiQL page bundled with Spring for GraphQL sends requests to the application's GraphQL endpoint, and the flaw lets an attacker-crafted URL cause the victim's browser to issue those requests and leak confidential information, potentially data the victim is authorized to see, to the attacker's website. Exploitation requires user interaction: the victim must open an attacker-supplied link pointing at the application's GraphiQL page. The attacker gains read access to sensitive GraphQL API data (high confidentiality impact only, with no integrity or availability impact per the scope-changed CVSS vector). Any application built on the affected Spring for GraphQL releases that exposes the bundled GraphiQL page is affected, including internal-only applications, since the victim only needs network access to the endpoint. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS is low (0.3%), so no exploitation is currently known.
What to do: Upgrade Spring for GraphQL to a release newer than your branch's affected range (later than 2.0.4, 1.4.6, 1.3.9, or 1.0.7) per the VMware/Spring advisory. As an interim mitigation, disable or restrict access to the bundled GraphiQL page in production and be cautious with untrusted links that resolve to /graphiql endpoints. Audit whether your GraphQL endpoint is internet-exposed and whether it returns sensitive data to authenticated user sessions.
| VMware Spring for GraphQL | 2.0.0 - 2.0.4 |
| VMware Spring for GraphQL | 1.4.0 - 1.4.6 |
| VMware Spring for GraphQL | 1.1.0 - 1.3.9 |
| VMware Spring for GraphQL | 1.0.0 - 1.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
- Vendors
- vmware
- Products
- spring for graphql
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.