CVE-2025-31496
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-31496 affects the Apollo Compiler, a query-based compiler for GraphQL. Before version 1.27.0, this vulnerability caused queries with deeply nested and reused named fragments to consume prohibitively large resources during validation. Named fragments were processed multiple times in some cases, leading to exponential resource usage when involved in deeply nested and reused fragments. This issue could result in excessive resource consumption and even denial-of-service in applications using the Apollo Compiler. The vulnerability has been addressed in version 1.27.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.