Information disclosure in Spring for GraphQL - CVE-2026-59288

 

Information disclosure in Spring for GraphQL - CVE-2026-59288

Published: August 31, 2026


Vulnerability identifier: #VU146425
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59288
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the GraphiQL page bundled with Spring for GraphQL when a victim with an active session follows a malicious link to the application's GraphiQL page. A remote attacker can share a malicious url to disclose sensitive information.

The application is vulnerable only when the GraphiQL endpoint is enabled and exposed, and user interaction is required.


Affected software

Spring for GraphQL

How to mitigate CVE-2026-59288

Install security update from vendor's website.

Spring for GraphQL - addressed in versions 1.0.8, 1.3.10, 1.4.7, 2.0.4.1, 2.0.5

External References

Related Security Bulletins