CVE-2025-32031
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-32031 is a vulnerability affecting the Apollo Gateway before version 2.10.1. This issue arises due to inefficient query planning in the gateway, which allows queries with deeply nested and reused named fragments to bypass internal optimizations. Consequently, planning times become significantly longer, leading to excessive resource consumption and potential denial of service. The query planner in Apollo Gateway does not enforce a timeout, enabling a small number of such queries to make the gateway inoperable. This vulnerability has been addressed in version 2.10.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Federation