Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-32380

Опубликовано: 09 апр. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. A vulnerability in Apollo Router's usage of Apollo Compiler allowed queries with deeply nested and reused named fragments to be prohibitively expensive to validate. This could lead to excessive resource consumption and denial of service. Apollo Router's usage of Apollo Compiler has been updated so that validation logic processes each named fragment only once, preventing redundant traversal. This has been remediated in apollo-router versions 1.61.2 and 2.1.1.

EPSS

Процентиль: 35%
0.00145
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
github
10 месяцев назад

Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing

EPSS

Процентиль: 35%
0.00145
Низкий

7.5 High

CVSS3

Дефекты

CWE-770