Apollographql Router vulnerabilities
11 known vulnerabilities affecting apollographql/router.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-32971P3CRITICALCVSS 9.0v>=1.44.0, <1.45.12024-05-02
CVE-2024-32971 [CRITICAL] CWE-440 CVE-2024-32971: Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that use
Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. The affected versions of Apollo Router contain a bug that in limited circumstances, could lead to unexpected operations being executed which can result in unintended data or effects. This only affects Router instances configur
nvd
CVE-2025-64173P3HIGHCVSS 7.5fixed in 1.61.12v>= 2.8.1-rc.0, < 2.8.12025-11-06
CVE-2025-64173 [HIGH] CWE-288 CVE-2025-64173: Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph usin
Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation 2. In versions 1.61.11 below, as well as 2.0.0-alpha.0 through 2.8.1-rc.0, a vulnerability allowed for unauthenticated queries to access data that required additional access controls. Router incorrectly handled access control directi
nvd
CVE-2025-64347P3HIGHCVSS 7.5fixed in 1.61.12v>= 2.8.1-rc.0, < 2.8.12025-11-07
CVE-2025-64347 [HIGH] CWE-284 CVE-2025-64347: Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using A
Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that were renamed via @link imports. Rou
nvd
CVE-2024-43783P3HIGHCVSS 7.5v>=1.7.0, < 1.52.12024-08-27
CVE-2024-43783 [HIGH] CWE-770 CVE-2024-43783: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and =1.7.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true: 1. Router has been configured to use a c
nvd
CVE-2025-32033P3HIGHCVSS 7.5fixed in 1.61.2v>= 2.0.0-alpha.0, < 2.1.12025-04-07
CVE-2025-32033 [HIGH] CWE-119 CVE-2025-32033: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, the operation limits plugin uses unsigned 32-bit integers to track limit counters (e.g. for a query's height). If a counter exceeded the maximum value for this data type (4,294,
nvd
CVE-2024-28101P3HIGHCVSS 7.5v>= 0.9.5, < 1.40.22024-03-21
CVE-2024-28101 [HIGH] CWE-409 CVE-2024-28101: The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo F
The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes` configuration option after the enti
nvd
CVE-2023-45812P3HIGHCVSS 7.5v>= 1.31.0, < 1.33.02023-10-18
CVE-2023-45812 [HIGH] CWE-754 CVE-2023-45812: The Apollo Router is a configurable, high-performance graph router written in Rust to run a federate
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses th
nvd
CVE-2025-32032P3HIGHCVSS 7.5fixed in 1.61.2v>= 2.0.0-alpha.0, < 2.1.12025-04-07
CVE-2025-32032 [HIGH] CWE-770 CVE-2025-32032: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically due to internal optimizations being frequently bypa
nvd
CVE-2025-32380P3HIGHCVSS 7.5fixed in 1.61.2v>= 2.0.0-alpha.0, < 2.1.12025-04-09
CVE-2025-32380 [HIGH] CWE-770 CVE-2025-32380: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This could lead to excessive resource c
nvd
CVE-2025-32034P3HIGHCVSS 7.5fixed in 1.61.2v>= 2.0.0-alpha.0, < 2.1.12025-04-07
CVE-2025-32034 [HIGH] CWE-770 CVE-2025-32034: The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a fed
The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Prior to 1.61.2 and 2.1.1, a vulnerability in Apollo Router allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment ex
nvd
CVE-2023-41317P4MEDIUMCVSS 5.9v>= 1.28.0, < 1.29.12023-09-05
CVE-2023-41317 [MEDIUM] CWE-755 CVE-2023-41317: The Apollo Router is a configurable, high-performance graph router written in Rust to run a federate
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when GraphQL Subscriptions are enabled. It can be triggered when **all of the foll
nvd