logo

Critical Spring GraphQL Deserialization Flaw Enables Remote Code Execution

ID: c70cc561-6175-5dfd-b2c5-3950a13e2cac

STIX ID: report--c70cc561-6175-5dfd-b2c5-3950a13e2cac

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Tamilselvan

...
...

A critical unsafe deserialization vulnerability (CVE-2026-59285, CVSS 9.2) in Spring for GraphQL using Jackson 2.x may allow remote code execution in applications with paginated GraphQL fields and certain gadget classes on the classpath. The advisory urges organizations to identify affected deployments (including transitive dependencies), prioritize internet-facing GraphQL services, apply the vendor's fixed releases, and use access controls and runtime defenses while patching. Sonatype estimated widespread downstream exposure among hundreds of thousands of components in the wider August Spring vulnerability disclosures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.