Apollo Federation是Apollo社区的一种以声明方式将 API 组合成统一图的架构。 Apollo Federation 2.10.1之前版本存在安全漏洞,该漏洞源于片段扩展处理不当,可能导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| apollographql | federation | < 2.10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-32031 | 7.5 HIGH | Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization |
| CVE-2025-32033 | 7.5 HIGH | Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow |
| CVE-2025-32034 | 7.5 HIGH | Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragmen |
| CVE-2025-32032 | 7.5 HIGH | Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization |
| CVE-2025-31496 | 7.5 HIGH | apollo-compiler Named Fragment Processing Vulnerability |
No comments yet