SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-59288

HIGH · CVSS 7.4 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The GraphiQL page in Spring for GraphQL versions 1.0.0 through 2.0.4 is vulnerable to an attack where an attacker can craft a malicious URL that, when accessed by a victim, may lead to the leakage of sensitive information from the victim's browser to the attacker's site. This vulnerability poses a significant risk to applications utilizing these versions of Spring for GraphQL, particularly those handling confidential data. Organizations using affected versions should prioritize remediation to mitigate potential data exposure risks.

CVE
CVE-2026-59288
Severity
HIGH
CVSS
7.4
EPSS
0.27%

Original NVD Description

The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

Related CVEs

Other vulnerabilities affecting the same vendor(s)