Spring for GraphQL 1.0-2.0.4 GraphiQL SRI missing - XSS risk
CVE-2026-59286 Published on August 27, 2026

Spring for GraphQL loads Untrusted Resources in GraphiQL support
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

NVD


Products Associated with CVE-2026-59286

Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.

 

Affected Versions

Spring for GraphQL: