cbcvebase.

Apollographql Federation vulnerabilities

4 known vulnerabilities affecting apollographql/federation.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4

Vulnerabilities

Page 1 of 1
CVE-2025-64530P3HIGHCVSS 7.5fixed in 2.9.5v>= 2.10.0-preview.0, < 2.10.4+2 more2025-11-13
CVE-2025-64530 [HIGH] CWE-288 CVE-2025-64530: Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulner Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation incorrectly allowed user-defined access
nvd
CVE-2024-43414P3HIGHCVSS 7.5v>= 2.0.0, < 2.8.5fixed in 1.52.12024-08-27
CVE-2024-43414 [HIGH] CWE-674 CVE-2024-43414: Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each tea Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and =2.0.0 and < 2.8.5 and Apollo Router <1.52.1 are also impacted through their use of @apollo/query
nvd
CVE-2025-32031P3HIGHCVSS 7.5fixed in 2.10.12025-04-07
CVE-2025-32031 [HIGH] CWE-770 CVE-2025-32031: Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being frequently bypassed. The query plan
nvd
CVE-2025-32030P3HIGHCVSS 7.5fixed in 2.10.12025-04-07
CVE-2025-32030 [HIGH] CWE-770 CVE-2025-32030: Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion. Named fragments were being expanded on
nvd
Apollographql Federation vulnerabilities | cvebase