CVE-2026-41856High· 7.5▾ TwilightThe Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.
Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
spring_for_graphql >= 1.0.0, < 1.0.7spring_for_graphql >= 1.3.0, < 1.3.9spring_for_graphql >= 1.4.0, < 1.4.5.1spring_for_graphql >= 2.0.0, < 2.0.3.1Upgrade past the affected range:
spring_for_graphql 2.0.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41700High· 8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking
CVE-2026-41699High· 8.1Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries
CVE-2026-41837Medium· 5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0…
CVE-2026-41728High· 7.5Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 throu…
CVE-2026-41006High· 7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations…
CVE-2026-1609High· 8.1A flaw was found in Keycloak