Known vulnerabilities in Spring for GraphQL
Vendor:
Broadcom
Software:
Spring for GraphQL
Software CPE:
cpe:2.3:a:broadcom:spring_for_graphql:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
1.0.8
2.0.4.1
1.4.7
1.3.10
1.3.9
1.3.8
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.7
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.9
1.2.8
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146426 - Allocation of Resources Without Limits or Throttling CVE-2026-59289 |
CWE-770 | Medium | 1.3.10, 1.4.7, 2.0.4.1, 2.0.5 | 31.08.2026 |
SB2026083164 |
||
| #VU146425 - Exposure of sensitive information to an unauthorized actor CVE-2026-59288 |
CWE-200 | Medium | 1.0.8, 1.3.10, 1.4.7, 2.0.4.1, 2.0.5 | 31.08.2026 |
SB2026083164 |
||
| #VU146424 - Allocation of Resources Without Limits or Throttling CVE-2026-59287 |
CWE-770 | Medium | 1.3.10, 1.4.7, 2.0.4.1, 2.0.5 | 31.08.2026 |
SB2026083164 |
||
| #VU146423 - Deserialization of Untrusted Data CVE-2026-59285 |
CWE-502 | High | 2.0.4.1, 2.0.5 | 31.08.2026 |
SB2026083164 |
||
| #VU146422 - Download of Code Without Integrity Check CVE-2026-59286 |
CWE-494 | Medium | 1.0.8, 1.3.10, 1.4.7, 2.0.4.1, 2.0.5 | 31.08.2026 |
SB2026083164 |