PT-2026-6185 · Apollo · @Apollo/Server/Standalone+1
Chalker
·
Published
2026-02-04
·
Updated
2026-05-06
·
CVE-2026-23897
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apollo Server versions 2.0.0 through 3.13.0
Apollo Server versions 4.2.0 through 4.13.0
Apollo Server versions 5.0.0 through 5.4.0
Description
Apollo Server, a GraphQL server, is susceptible to denial of service (DoS) attacks. This occurs due to the default configuration of the
startStandaloneServer function from the @apollo/server/standalone package. Specifically, specially crafted request bodies containing unusual character set encodings can trigger the issue. The issue only affects users directly utilizing startStandaloneServer and does not impact those integrating Apollo Server through packages like @as-integrations/express5 or @as-integrations/next.Recommendations
Versions 2.0.0 through 3.13.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Versions 4.2.0 through 4.13.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Versions 5.0.0 through 5.4.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Apollo/Server/Standalone
Apollo Server