Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
Published Apr 7, 2025
7.5
HIGHCVSS 3.1
EPSS 0.51%
Description
Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries with deeply nested and reused named fragments to be prohibitively expensive to query plan, specifically during named fragment expansion. Named fragments were being expanded once per fragment spread during query planning, leading to exponential resource usage when deeply nested and reused fragments were involved. This could lead to excessive resource consumption and denial of service. This has been remediated in @apollo/gateway version 2.10.1.
Affected products
-
- Version < 2.10.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apollographql | Federation | n/a |
|
- < 2.10.1
No data.
No Red Hat product state for this CVE.
@apollo/gateway
npm
Introduced 0 Fixed 2.10.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @apollo/gateway | 0 | 2.10.1 |
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10283 Advisory
- https://github.com/advisories/GHSA-q2f9-x4p4-7xmh Advisory
- https://github.com/apollographql/federation/pull/3236 x_refsource_MISCIssue TrackingPatch
- https://github.com/apollographql/federation/releases/tag/%40apollo%2Fgateway%402.10.1 x_refsource_MISCRelease Notes
- https://github.com/apollographql/federation/security/advisories/GHSA-q2f9-x4p4-7xmh x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-32030
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10283 | Advisory | |
| https://github.com/advisories/GHSA-q2f9-x4p4-7xmh | Advisory | |
| https://github.com/apollographql/federation/pull/3236 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/apollographql/federation/releases/tag/%40apollo%2Fgateway%402.10.1 | x_refsource_MISCRelease Notes | |
| https://github.com/apollographql/federation/security/advisories/GHSA-q2f9-x4p4-7xmh | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-32030 |
Change history (0)
No recorded changes yet.