A AegiFlow
HIGHCVSS 8.1EPSS 0.2%

CVE-2026-41700

CVE-2026-41700 updated by NVD

Published
2026-06-11
Modified
2026-08-21
EPSS percentile
9%
Sources
github-advisory, nvd

Summary

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.springframework.graphql:spring-graphql2.0.4, 1.4.6

Remediation: Upgrade to 2.0.4 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.