Affected versions:
Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-41699 |
|
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* |
Thu, 11 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
|
| Vendors & Products |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8. | |
| Title | Unsafe Deserialization in Spring GraphQL | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-11T14:43:08.813Z
Reserved: 2026-04-22T06:21:22.982Z
Link: CVE-2026-41699
Updated: 2026-06-11T14:43:05.314Z
Status : Analyzed
Published: 2026-06-11T07:16:28.280
Modified: 2026-06-12T19:28:55.920
Link: CVE-2026-41699
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:12Z