Executive brief
Spring for GraphQL is a library that provides GraphQL integration for Spring applications. The bundled GraphiQL interactive development page loads JavaScript libraries directly from public content delivery networks (CDNs) without integrity validation. An attacker who can intercept or compromise the CDN could inject malicious JavaScript code that executes in the browser of anyone accessing the GraphiQL interface, potentially enabling account takeover, data theft, or further network compromise.
Technical details
This vulnerability is an integrity validation bypass in which the GraphiQL page references external JavaScript libraries from public CDNs without implementing Subresource Integrity (SRI) checks. The absence of SRI checksums allows a man-in-the-middle attacker, DNS hijacker, or compromised CDN to serve malicious JavaScript that will execute with the privileges of the authenticated user accessing the GraphiQL page. No authentication or special network position is strictly required if the attacker can influence the HTTP response. The vulnerability affects Spring for GraphQL versions 1.0.0 through 2.0.4 across multiple minor version branches. Patches to add SRI validation are expected from the vendor.
Affected products
- VMware Spring for GraphQL 1.0.0–1.0.7, 1.1.0–1.3.9, 1.4.0–1.4.6, 2.0.0–2.0.4
Timeline
- 2026-08-27: disclosed