Back

HIGH

Spring for GraphQL Information Exposure in GraphiQL support

Published Aug 27, 2026

Description

The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Aug 27, 2026
Updated Sep 1, 2026
Reserved Jul 4, 2026
CISA Vulnrichment
Updated Sep 1, 2026
NVD
Status Modified
Modified Sep 1, 2026
Red Hat
Severity n/a
Public date n/a