CVE-2025-32031

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 770

Summary

CVE-2025-32031 is a vulnerability affecting the Apollo Gateway before version 2.10.1. This issue arises due to inefficient query planning in the gateway, which allows queries with deeply nested and reused named fragments to bypass internal optimizations. Consequently, planning times become significantly longer, leading to excessive resource consumption and potential denial of service. The query planner in Apollo Gateway does not enforce a timeout, enabling a small number of such queries to make the gateway inoperable. This vulnerability has been addressed in version 2.10.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share