CVE-2026-59286
N/A
N/A
Summary
The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring for GraphQL | 2.0.0 <= 2.0.4 | affected |
| Spring | Spring for GraphQL | 1.4.0 <= 1.4.6 | affected |
| Spring | Spring for GraphQL | 1.1.0 <= 1.3.9 | affected |
| Spring | Spring for GraphQL | 1.0.0 <= 1.0.7 | affected |
Weaknesses
- CWE-494 Download of Code Without Integrity Check
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.