SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59285

HIGH · CVSS 8.1 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Spring for GraphQL versions 2.0.0 to 2.0.4 are vulnerable to unsafe deserialization when handling paginated GraphQL queries, potentially allowing attackers to exploit this flaw to execute arbitrary code. Organizations utilizing these specific versions in their GraphQL applications should prioritize remediation to mitigate the risk of unauthorized access and data manipulation. Immediate action is recommended for developers and security teams managing applications built on this framework.

CVE
CVE-2026-59285
Severity
HIGH
CVSS
8.1
EPSS
0.48%

Original NVD Description

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4

Related CVEs

Other vulnerabilities affecting the same vendor(s)