CVE-2026-41700: VMware Spring For Graphql
High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
Affected products
- VMware Spring For Graphql: from 1.0.0, before 1.0.7 (fixed in 1.0.7); from 1.3.0, before 1.3.9 (fixed in 1.3.9); from 1.4.0, before 1.4.5.1 (fixed in 1.4.5.1); from 2.0.0, before 2.0.3.1 (fixed in 2.0.3.1)
Published 2026-06-11. Last modified 2026-07-23.