← Vulnerability feed

Vulnerability record · CVE-2026-41699 · published 11 June 2026

CVE-2026-41699: Vmware spring for graphql deserialization of untrusted data vulnerability

Vmware · Spring For Graphql

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.

9.8 CVSS 3.1 Critical EPSS 0.68% · top 49.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41699 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-59285Vmware spring for graphql deserialization of untrusted data vulnerabilitySpring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4EPSS 0.44%8.1CVE-2026-59286Vmware spring for graphql download of code without integrity check vulnerabilityThe GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can…EPSS 0.33%8.1CVE-2026-41700Vmware spring for graphql origin validation error vulnerabilitySpring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an …EPSS 0.23%7.5CVE-2026-59289Vmware spring for graphql allocation without limits vulnerabilitySpring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlyin…EPSS 0.46%7.5CVE-2026-41856Vmware spring for graphql improper access control vulnerabilityThe Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarch…EPSS 0.39%7.4CVE-2026-59288Vmware spring for graphql information exposure vulnerabilityThe GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL s…EPSS 0.37%5.9CVE-2026-59287Vmware spring for graphql allocation without limits vulnerabilitySpring for GraphQL is vulnerable to Denial of Service attacks when using the WebSocket client with keepAlive enabled. Spring for GraphQL 2.0.0 - 2.0.…EPSS 0.37%4.3CVE-2023-34047Vmware spring for graphql vulnerabilityA batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including secur…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2026-41699), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.