Intel

AIKIDO-2026-236725

spring-graphql is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted DataCVE-2026-41699 Published Today

81

High Risk

This Affects:

JAVAspring-graphql
0.0.1 - 1.3.8
Fixed in 1.3.9
1.4.0 - 1.4.5
Fixed in 1.4.6
2.0.0 - 2.0.3
Fixed in 2.0.4
Are you affected? Scan for Free

TL;DR

Spring for GraphQL contains an unsafe deserialization vulnerability in the processing of paginated GraphQL queries. Applications that expose paginated (Connection) fields and include certain gadget classes on the classpath may allow attackers to submit specially crafted GraphQL requests that trigger unintended object deserialization behavior. Successful exploitation can lead to remote code execution on the affected system.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-graphql is vulnerable to Deserialization of Untrusted Data in versions 2.0.0 - 2.0.3, 1.4.0 - 1.4.5 and 0.0.1 - 1.3.8.

How to fix this

Upgrade the org.springframework.graphql:spring-graphql library to the patch version.