CVE-2026-59285: VMware Spring For Graphql

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4

Affected products

  • VMware Spring For Graphql: from 2.0.0, before 2.0.4.1 (fixed in 2.0.4.1)

Published 2026-08-27. Last modified 2026-09-02.