CVE-2025-32030

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 770

Summary

CVE-2025-32030 affects Apollo Gateway, a tool used to combine multiple GraphQL microservices into a single endpoint. Before version 2.10.1, the software contained a vulnerability that caused queries with deeply nested and reused named fragments to be excessively resource-intensive during query planning. Named fragments were expanded repeatedly during this process, resulting in exponential resource usage and the risk of denial of service. This issue has since been addressed in version 2.10.1 of @apollo/gateway.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share