CVE-2025-31496

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 770

Summary

CVE-2025-31496 affects the Apollo Compiler, a query-based compiler for GraphQL. Before version 1.27.0, this vulnerability caused queries with deeply nested and reused named fragments to consume prohibitively large resources during validation. Named fragments were processed multiple times in some cases, leading to exponential resource usage when involved in deeply nested and reused fragments. This issue could result in excessive resource consumption and even denial-of-service in applications using the Apollo Compiler. The vulnerability has been addressed in version 1.27.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share