Critical Spring GraphQL Deserialization Flaw Enables Remote Code Execution
ID: c70cc561-6175-5dfd-b2c5-3950a13e2cac
STIX ID: report--c70cc561-6175-5dfd-b2c5-3950a13e2cac
Feed Name: Cyber Press
A critical unsafe deserialization vulnerability (CVE-2026-59285, CVSS 9.2) in Spring for GraphQL using Jackson 2.x may allow remote code execution in applications with paginated GraphQL fields and certain gadget classes on the classpath. The advisory urges organizations to identify affected deployments (including transitive dependencies), prioritize internet-facing GraphQL services, apply the vendor's fixed releases, and use access controls and runtime defenses while patching. Sonatype estimated widespread downstream exposure among hundreds of thousands of components in the wider August Spring vulnerability disclosures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
