CVE-2026-59287
N/A
N/A
Summary
Spring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.3.0 - 1.3.9
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring for GraphQL | 2.0.0 <= 2.0.4 | affected |
| Spring | Spring for GraphQL | 1.4.0 <= 1.4.6 | affected |
| Spring | Spring for GraphQL | 1.3.0 <= 1.3.9 | affected |
Weaknesses
- CWE-770 Allocation of Resources Without Limits or Throttling
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.