SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59289

HIGH · CVSS 7.5 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Spring for GraphQL versions 1.2.0 to 2.0.4 are vulnerable to a Denial of Service (DoS) attack due to improper handling of client-supplied values in scrollable queries, which can lead to excessive memory consumption or significant load on the datastore. Organizations using these versions should prioritize patching to mitigate the risk of service disruption caused by maliciously crafted queries. This vulnerability is particularly relevant for developers and system administrators managing applications that utilize Spring for GraphQL.

CVE
CVE-2026-59289
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9

Related CVEs

Other vulnerabilities affecting the same vendor(s)