Spring for GraphQL 1.0-2.0.4 GraphiQL SRI missing - XSS risk
CVE-2026-59286 Published on August 27, 2026
Spring for GraphQL loads Untrusted Resources in GraphiQL support
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page.
Spring for GraphQL 2.0.0 - 2.0.4
Spring for GraphQL 1.4.0 - 1.4.6
Spring for GraphQL 1.1.0 - 1.3.9
Spring for GraphQL 1.0.0 - 1.0.7
Products Associated with CVE-2026-59286
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring for GraphQL:- Version 2.0.0, <= 2.0.4 is affected.
- Version 1.4.0, <= 1.4.6 is affected.
- Version 1.1.0, <= 1.3.9 is affected.
- Version 1.0.0, <= 1.0.7 is affected.