CVE-2026-59289
N/A
N/A
Summary
Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.2.0 - 1.3.9
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring for GraphQL | 2.0.0 <= 2.0.4 | affected |
| Spring | Spring for GraphQL | 1.4.0 <= 1.4.6 | affected |
| Spring | Spring for GraphQL | 1.2.0 <= 1.3.9 | affected |
Weaknesses
- CWE-770 Allocation of Resources Without Limits or Throttling
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.