CVE-2023-34047: VMware Spring For Graphql

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A batch loader function in Spring for GraphQL versions 1.1.0 - 1.1.5 and 1.2.0 - 1.2.2 may be exposed to GraphQL context with values, including security context values, from a different session. An application is vulnerable if it provides a DataLoaderOptions instance when registering batch loader functions through DefaultBatchLoaderRegistry.

Affected products

  • VMware Spring For Graphql: from 1.1.0, up to and including 1.1.5; from 1.2.0, up to and including 1.2.2

Published 2023-09-20. Last modified 2026-06-17.