Apollographql Federation vulnerabilities
4 known vulnerabilities affecting apollographql/federation.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4
Vulnerabilities
Page 1 of 1
CVE-2025-64530P3HIGHCVSS 7.5fixed in 2.9.5v>= 2.10.0-preview.0, < 2.10.4+2 more2025-11-13
CVE-2025-64530 [HIGH] CWE-288 CVE-2025-64530: Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulner
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation incorrectly allowed user-defined access
nvd
CVE-2024-43414P3HIGHCVSS 7.5v>= 2.0.0, < 2.8.5fixed in 1.52.12024-08-27
CVE-2024-43414 [HIGH] CWE-674 CVE-2024-43414: Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each tea
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and =2.0.0 and < 2.8.5 and Apollo Router <1.52.1 are also impacted through their use of @apollo/query
nvd
CVE-2025-32031P3HIGHCVSS 7.5fixed in 2.10.12025-04-07
CVE-2025-32031 [HIGH] CWE-770 CVE-2025-32031: Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being frequently bypassed. The query plan
nvd
CVE-2025-32030P3HIGHCVSS 7.5fixed in 2.10.12025-04-07
CVE-2025-32030 [HIGH] CWE-770 CVE-2025-32030: Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion. Named fragments were being expanded on
nvd