Логотип exploitDog
bind:CVE-2026-23897
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23897

Количество 2

Количество 2

nvd логотип

CVE-2026-23897

4 дня назад

Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to denial of service (DoS) attacks through specially crafted request bodies with exotic character set encodings. This issue does not affect users that use @apollo/server as a dependency for integration packages, like @as-integrations/express5 or @as-integrations/next, only direct usage of startStandaloneServer.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mp6q-xf9x-fwf7

4 дня назад

Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23897

Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before 4.13.0, and 5.0.0 to before 5.4.0, the default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to denial of service (DoS) attacks through specially crafted request bodies with exotic character set encodings. This issue does not affect users that use @apollo/server as a dependency for integration packages, like @as-integrations/express5 or @as-integrations/next, only direct usage of startStandaloneServer.

CVSS3: 7.5
0%
Низкий
4 дня назад
github логотип
GHSA-mp6q-xf9x-fwf7

Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`

CVSS3: 7.5
0%
Низкий
4 дня назад

Уязвимостей на страницу