CVE-2026-41856: Spring GraphQL Annotation Detection Vulnerability
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are used for authorization decisions. When all conditions are met, security annotations can be ignored at runtime.
Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41856?
The severity of CVE-2026-41856 is high, with a score of 7.5.
What is the impact of CVE-2026-41856?
CVE-2026-41856 can potentially allow security annotations for authorization decisions to be ignored.
How do I fix CVE-2026-41856?
To fix CVE-2026-41856, update to the latest version of Spring for GraphQL that addresses this vulnerability.
Who is affected by CVE-2026-41856?
Applications utilizing Spring for GraphQL and relying on security annotations in type hierarchies are affected by CVE-2026-41856.
What versions of Spring for GraphQL are vulnerable under CVE-2026-41856?
The specific versions of Spring for GraphQL vulnerable to CVE-2026-41856 are not listed, but users should consult the latest security advisories or release notes.