SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59287

MEDIUM · CVSS 5.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Spring for GraphQL is susceptible to Denial of Service (DoS) attacks when the WebSocket client is configured with keepAlive enabled, affecting versions 1.3.0 through 2.0.4. This vulnerability could allow an attacker to disrupt service availability, making it critical for organizations utilizing these specific versions to prioritize remediation. Users of affected Spring for GraphQL versions should assess their exposure and implement necessary mitigations promptly.

CVE
CVE-2026-59287
Severity
MEDIUM
CVSS
5.9
EPSS
0.27%

Original NVD Description

Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9

Related CVEs

Other vulnerabilities affecting the same vendor(s)