Executive brief
Spring for GraphQL is a framework that enables applications to serve GraphQL APIs using Spring. When an application exposes paginated query results (Connection fields) and has certain classes on its classpath, an unauthenticated attacker can send a specially crafted GraphQL request that triggers unsafe deserialization, leading to remote code execution. This allows complete compromise of the affected application without requiring any user interaction or special privileges.
Technical details
This vulnerability is classified as unsafe deserialization (CWE-502) affecting the pagination (Connection) handling in Spring for GraphQL. The root cause involves improper validation of serialized objects during deserialization of GraphQL request variables. An attacker can craft a malicious GraphQL query with specially constructed variables that exploit this deserialization flaw. The attack requires network access to the GraphQL endpoint and does not require authentication, user interaction, or elevated privileges. Successful exploitation allows remote code execution with the privileges of the application. Patches are available: version 2.0.4, 1.4.6 for affected versions, though version 1.3.0–1.3.8 may have limited patching options.
Affected products
- VMware Spring for GraphQL 2.0.0 through 2.0.3
- VMware Spring for GraphQL 1.4.0 through 1.4.5
- VMware Spring for GraphQL 1.3.0 through 1.3.8
Timeline
- 2026-06-11: disclosed: Vulnerability published by GitHub Advisory Database
- 2026-05-21: patched: Fix committed to upstream repository (commit 5579b6e)