PT-2025-15756 · Apollo · Apollo Router
Yo-Artyom
·
Published
2025-04-07
·
Updated
2025-04-14
·
CVE-2025-32380
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Apollo Router versions prior to 1.61.2
Apollo Router versions prior to 2.1.1
Description:
A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate, leading to excessive resource consumption and denial of service. The issue has been remediated by updating the validation logic to process each named fragment only once, preventing redundant traversal.
Recommendations:
For Apollo Router versions prior to 1.61.2, update to version 1.61.2 or later to resolve the issue.
For Apollo Router versions prior to 2.1.1, update to version 2.1.1 or later to resolve the issue.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apollo Router