SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59286

HIGH · CVSS 8.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The GraphiQL page in specific versions of Spring for GraphQL is vulnerable due to the loading of JavaScript libraries from a public CDN without Subresource Integrity checks, allowing an attacker to inject malicious code. This could lead to arbitrary code execution in the browser of any user accessing the affected GraphiQL page. Organizations using the specified versions of Spring for GraphQL should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-59286
Severity
HIGH
CVSS
8.1
EPSS
0.25%
Java

Original NVD Description

The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

Related CVEs

Other vulnerabilities affecting the same vendor(s)