CVE-2025-32034

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 7, 2025
Updated: Apr 8, 2025
CWE ID 770

Summary

CVE-2025-32034 affects the Apollo Router Core, a configurable graph router used in Apollo Federation 2 for federated supergraphs. Before versions 1.61.2 and 2.1.1, a vulnerability in the router resulted in prohibitively expensive query planning during named fragment expansion. Named fragments were expanded excessively during this process, causing resource usage to grow exponentially with deeply nested and reused fragments. This issue could potentially lead to significant resource consumption and denial of service attacks. The vulnerability has been addressed in the latest versions of apollo-router.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share