CVE-2026-41700High· 8.1▾ TwilightSpring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials.
Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
spring_for_graphql >= 1.0.0, < 1.0.7spring_for_graphql >= 1.3.0, < 1.3.9spring_for_graphql >= 1.4.0, < 1.4.5.1spring_for_graphql >= 2.0.0, < 2.0.3.1Upgrade past the affected range:
spring_for_graphql 2.0.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41856High· 7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies
CVE-2026-41699High· 8.1Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries
CVE-2026-59318Medium· 6.5In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched
CVE-2026-59308Medium· 4.2In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
CVE-2026-59279High· 7.5The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated
CVE-2026-59310Critical· 9.8vCenter directory-traversal vulnerability