Threat Advisory

Spring GraphQL Flaw Enables Remote Code Execution via Unsafe Deserialization

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Spring GraphQL versions 2.0.x, 1.4.x, 1.3.x, 1.1.x, and 1.0.x depending on the CVE. The deserialization flaw hits only 2.0.0 through 2.0.4. Spring Cloud Commons, Gateway, and Config each list their own affected ranges across 3.1.x through 5.0.x.

CVE-2026-59285 (CVSS 9.8 — Critical): This vulnerability affects Spring for GraphQL 2.0.0 through 2.0.4 and triggers under specific conditions where the app exposes a paginated Connection field using Jackson 2.x and has gadget classes in its classpath. An attacker can craft a request that deserializes an attacker-controlled cursor, leading to unintended logic execution and remote code execution.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting Spring GraphQL versions 2.0.x, 1.4.x, 1.3.x, 1.1.x, and 1.0.x depending on the CVE. The deserialization flaw hits only 2.0.0 through 2.0.4. Spring Cloud Commons, Gateway, and Config each list their own affected ranges across 3.1.x through 5.0.x.

CVE-2026-59285 (CVSS 9.8 — Critical): This vulnerability affects Spring for GraphQL 2.0.0 through 2.0.4 and triggers under specific conditions where the app exposes a paginated Connection field using Jackson 2.x and has gadget classes in its classpath. An attacker can craft a request that deserializes an attacker-controlled cursor, leading to unintended logic execution and remote code execution.[emaillocker id="1283"]

CVE-2026-59289 (CVSS 8.1 — High): This vulnerability causes denial of service via pagination by auto-registering data fetchers that forward client values directly to the repository. An attacker can forge a Connection query that drains memory or pins heavy load on the datastore.

CVE-2026-59288 (CVSS 5.3 — Medium): The bundled GraphiQL page leaks confidential information from an active session through a malicious link.

CVE-2026-59286 (CVSS 4.3 — Medium): The bundled GraphiQL page loads CDN scripts without Subresource Integrity checks, allowing injected scripts to run in the victim browser if the CDN is compromised.

CVE-2026-59284: This vulnerability lacks an allow list for the writable env actuator endpoint.

CVE-2026-47879 (CVSS 7.5 — High): This vulnerability lets Spring Cloud Gateway read arbitrary resource locations for gRPC proto descriptors.

CVE-2026-47836 (CVSS 6.4 — Medium): This vulnerability exposes the Config Server to a TOCTOU race when cloning SVN repositories.

These vulnerabilities collectively present a significant risk, particularly for administrators who manage production APIs built on the Spring stack.

RECOMMENDATION:

We recommend you to update Spring GraphQL to the version 2.0.5, Spring Cloud Commons to the version 5.0.3, Gateway to the version 5.0.3, Config to the version 5.0.5.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu