Apollographql Apollo Router vulnerabilities
5 known vulnerabilities affecting apollographql/apollo_router.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-43783P3HIGHCVSS 7.5≥ 1.7.0, < 1.52.12024-08-27
CVE-2024-43783 [HIGH] CWE-770 CVE-2024-43783: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and =1.7.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true: 1. Router has been configured to use a c
nvd
CVE-2024-43414P3HIGHCVSS 7.5fixed in 1.52.12024-08-27
CVE-2024-43414 [HIGH] CWE-674 CVE-2024-43414: Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each tea
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and =2.0.0 and < 2.8.5 and Apollo Router <1.52.1 are also impacted through their use of @apollo/query
nvd
CVE-2024-28101P3HIGHCVSS 7.5≥ 0.9.5, < 1.40.22024-03-21
CVE-2024-28101 [HIGH] CWE-409 CVE-2024-28101: The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo F
The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes` configuration option after the enti
nvd
CVE-2023-45812P3HIGHCVSS 7.5≥ 1.31.0, ≤ 1.32.02023-10-18
CVE-2023-45812 [HIGH] CWE-754 CVE-2023-45812: The Apollo Router is a configurable, high-performance graph router written in Rust to run a federate
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses th
nvd
CVE-2023-41317P4MEDIUMCVSS 5.9≥ 1.28.0, < 1.29.12023-09-05
CVE-2023-41317 [MEDIUM] CWE-755 CVE-2023-41317: The Apollo Router is a configurable, high-performance graph router written in Rust to run a federate
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be triggered when **all of the foll
nvd