{"api_version":"1","generated_at":"2026-08-30T21:17:56+00:00","cve":"CVE-2026-59289","urls":{"html":"https://cve.report/CVE-2026-59289","api":"https://cve.report/api/cve/CVE-2026-59289.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-59289","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-59289"},"summary":{"title":"Spring for GraphQL Denial of Service via pagination support","description":"Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service.\nSpring for GraphQL 2.0.0 - 2.0.4\nSpring for GraphQL 1.4.0 - 1.4.6\nSpring for GraphQL 1.2.0 - 1.3.9","state":"PUBLISHED","assigner":"vmware","published_at":"2026-08-27 20:17:55","updated_at":"2026-08-28 18:47:30"},"problem_types":["CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":[],"references":[{"url":"https://spring.io/security/cve-2026-59289","name":"https://spring.io/security/cve-2026-59289","refsource":"security@vmware.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59289","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59289","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Spring","product":"Spring for GraphQL","version":"affected 2.0.0 2.0.4 custom","platforms":[]},{"source":"CNA","vendor":"Spring","product":"Spring for GraphQL","version":"affected 1.4.0 1.4.6 custom","platforms":[]},{"source":"CNA","vendor":"Spring","product":"Spring for GraphQL","version":"affected 1.2.0 1.3.9 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"59289","cve":"CVE-2026-59289","epss":"0.001560000","percentile":"0.050410000","score_date":"2026-08-29","updated_at":"2026-08-30 00:07:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Spring for GraphQL","vendor":"Spring","versions":[{"lessThanOrEqual":"2.0.4","status":"affected","version":"2.0.0","versionType":"custom"},{"lessThanOrEqual":"1.4.6","status":"affected","version":"1.4.0","versionType":"custom"},{"lessThanOrEqual":"1.3.9","status":"affected","version":"1.2.0","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service.</p><p>Spring for GraphQL 2.0.0 - 2.0.4<br/>Spring for GraphQL 1.4.0 - 1.4.6<br/>Spring for GraphQL 1.2.0 - 1.3.9</p>"}],"value":"Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service.\nSpring for GraphQL 2.0.0 - 2.0.4\nSpring for GraphQL 1.4.0 - 1.4.6\nSpring for GraphQL 1.2.0 - 1.3.9"}],"impacts":[{"descriptions":[{"lang":"en","value":"Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service."}]}],"problemTypes":[{"descriptions":[{"description":"CWE-770 Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-27T17:57:47.944Z","orgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","shortName":"vmware"},"references":[{"url":"https://spring.io/security/cve-2026-59289"}],"source":{"discovery":"UNKNOWN"},"title":"Spring for GraphQL Denial of Service via pagination support"}},"cveMetadata":{"assignerOrgId":"dcf2e128-44bd-42ed-91e8-88f912c1401d","assignerShortName":"vmware","cveId":"CVE-2026-59289","datePublished":"2026-08-27T17:57:47.944Z","dateReserved":"2026-07-04T18:13:34.323Z","dateUpdated":"2026-08-27T17:57:47.944Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-27 20:17:55","lastModifiedDate":"2026-08-28 18:47:30","problem_types":["CWE-770 Allocation of Resources Without Limits or Throttling"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"59289","Ordinal":"1","Title":"Spring for GraphQL Denial of Service via pagination support","CVE":"CVE-2026-59289","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"59289","Ordinal":"1","NoteData":"Spring for GraphQL's Spring Data pagination support resolves arguments of a scrollable query and forwards the client-supplied values to the underlying repository. An attacker can forge a malicious query for a Connection field that can exhaust application memory or place significant, prolonged load on the underlying datastore, resulting in a Denial of Service.\nSpring for GraphQL 2.0.0 - 2.0.4\nSpring for GraphQL 1.4.0 - 1.4.6\nSpring for GraphQL 1.2.0 - 1.3.9","Type":"Description","Title":"Spring for GraphQL Denial of Service via pagination support"}]}}}