CVE-2025-32032

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 770

Summary

CVE-2025-32032 is a vulnerability affecting the Apollo Router Core, a high-performance graph router for Apollo Federation 2. The issue arises from a bypass of internal optimizations in the query planner. Queries with deeply nested and reused named fragments can generate numerous selections where the optimization does not apply, leading to prolonged planning times. Since the query planner lacks a timeout, a limited number of such queries can exhaust the router's thread pool, causing excessive resource consumption and denial of service. This vulnerability has been mitigated in apollo-router versions 1.61.2 and 2.1.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share