All 4 CVE vulnerabilities found in federation, with AI-generated Chinese analysis, references, and POCs.
Vendor: apollographql
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-64530 | @apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields CWE-288 | 7.5 | High | 2025-11-13 |
| CVE-2025-32031 | Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass CWE-770 | 7.5 | High | 2025-04-07 |
| CVE-2025-32030 | Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion CWE-770 | 7.5 | High | 2025-04-07 |
| CVE-2024-43414 | Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries CWE-674 | 7.5 | High | 2024-08-27 |
All 4 known CVE vulnerabilities affecting federation with full Chinese analysis, references, and POCs where available.