GHSA-m39w-hqxx-3r48HighCVSS 8.1

Spring for GraphQL: Cross-Site WebSocket Hijacking

Published
June 11, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials.

Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

🎯 Affected products4

  • maven/org.springframework.graphql:spring-graphql:>= 2.0.0, <= 2.0.3
  • maven/org.springframework.graphql:spring-graphql:>= 1.4.0, <= 1.4.5
  • maven/org.springframework.graphql:spring-graphql:>= 1.3.0, <= 1.3.8
  • maven/org.springframework.graphql:spring-graphql:>= 1.0.0, <= 1.0.6

🔗 References (4)