Affected versions:
Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-41700 |
|
Fri, 12 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* |
Thu, 11 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
|
| Vendors & Products |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6. | |
| Title | Cross-Site WebSocket Hijacking in Spring for GraphQL | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-11T14:43:36.170Z
Reserved: 2026-04-22T06:21:22.982Z
Link: CVE-2026-41700
Updated: 2026-06-11T14:43:33.111Z
Status : Analyzed
Published: 2026-06-11T07:16:28.400
Modified: 2026-06-12T14:13:50.790
Link: CVE-2026-41700
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:11Z