Download of code without integrity check in Spring for GraphQL - CVE-2026-59286

 

Download of code without integrity check in Spring for GraphQL - CVE-2026-59286

Published: August 31, 2026


Vulnerability identifier: #VU146422
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59286
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code in the browser and disclose sensitive information.

The vulnerability exists due to download of code without integrity check in the bundled GraphiQL page when loading JavaScript libraries from a public CDN. A remote attacker can inject malicious code into those scripts to execute arbitrary code in the browser and disclose sensitive information.

Exploitation requires the GraphiQL endpoint to be enabled and exposed, and the CDN or the network path to it to be compromised.


Affected software

Spring for GraphQL

How to mitigate CVE-2026-59286

Install security update from vendor's website.

Spring for GraphQL - addressed in versions 1.0.8, 1.3.10, 1.4.7, 2.0.4.1, 2.0.5

External References

Related Security Bulletins