VMware Spring for GraphQL是美国威睿(VMware)公司的一个GraphQL应用开发框架。 VMware Spring for GraphQL 2.0.0及之前版本、1.4.0及之前版本、1.3.0及之前版本和1.0.0及之前版本存在访问控制错误漏洞,该漏洞源于@Controller数据获取器的注解检测机制在类型层次结构中可能无法正确解析注解,可能导致安全注解在运行时被忽略。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring for GraphQL | 2.0.0< 2.0.3.1 |
affected |
1.4.0< 1.4.5.1 |
affected | ||
1.3.0< 1.3.9 |
affected | ||
1.0.0< 1.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring for GraphQL | 2.0.0 ~ 2.0.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40999 | 8.6 HIGH | Spring WS SSRF via unvalidated WS-Addressing reply destinations |
| CVE-2026-40994 | 8.2 HIGH | Wss4jSecurityInterceptor disables WS-I BSP validation by default |
| CVE-2026-40998 | 8.2 HIGH | Jaxp13 XPath XXE via StreamSource and SAXSource |
| CVE-2026-41699 | 8.1 HIGH | Unsafe Deserialization in Spring GraphQL |
| CVE-2026-41700 | 8.1 HIGH | Cross-Site WebSocket Hijacking in Spring for GraphQL |
| CVE-2026-40987 | 7.1 HIGH | Remote-file synchronizer in Spring Integration writes server-supplied filename under local |
| CVE-2026-40985 | 6.4 MEDIUM | Data Binding Vulnerability in Spring Web Flow with Unified EL Parser |
| CVE-2026-40995 | 5.4 MEDIUM | X.509 authentication bypasses Spring Security account checks |
| CVE-2026-40997 | 5.3 MEDIUM | SOAP security faults leak Spring Security account state |
| CVE-2026-41001 | 5.3 MEDIUM | Predictable Temp Directory in Artemis Auto-configuration |
| CVE-2026-40992 | 5.0 MEDIUM | Mail Auto-Configuration Does Not Enable SSL Hostname Verification |
| CVE-2026-40986 | 4.8 MEDIUM | Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML |
| CVE-2026-40996 | 4.8 MEDIUM | Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default |
| CVE-2026-41000 | 3.7 LOW | WSS4J validation does not use configured replay cache |
No comments yet