Affected versions:
Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-41856 |
|
Fri, 12 Jun 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:vmware:spring_for_graphql:*:*:*:*:*:*:*:* |
Thu, 11 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
|
| Vendors & Products |
Spring
Spring spring For Graphql Vmware Vmware spring For Graphql |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6. | |
| Title | Spring GraphQL Annotation Detection Vulnerability | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-11T15:16:55.976Z
Reserved: 2026-04-22T06:22:10.081Z
Link: CVE-2026-41856
Updated: 2026-06-11T15:16:52.674Z
Status : Analyzed
Published: 2026-06-11T07:16:28.513
Modified: 2026-06-12T14:14:06.457
Link: CVE-2026-41856
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:09Z