VYPR

Graphql Java Spring

by Graphql Java

CVEs (1)

  • CVE-2026-59286Aug 27, 2026
    risk 0.00cvss epss

    The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL…