CVE-2025-32034
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-32034 affects the Apollo Router Core, a configurable graph router used in Apollo Federation 2 for federated supergraphs. Before versions 1.61.2 and 2.1.1, a vulnerability in the router resulted in prohibitively expensive query planning during named fragment expansion. Named fragments were expanded excessively during this process, causing resource usage to grow exponentially with deeply nested and reused fragments. This issue could potentially lead to significant resource consumption and denial of service attacks. The vulnerability has been addressed in the latest versions of apollo-router.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Router