Information disclosure in Spring for GraphQL - CVE-2026-59288
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the GraphiQL page bundled with Spring for GraphQL when a victim with an active session follows a malicious link to the application's GraphiQL page. A remote attacker can share a malicious url to disclose sensitive information.
The application is vulnerable only when the GraphiQL endpoint is enabled and exposed, and user interaction is required.