Loading...
Skip to main content

CVE-2025-64347

HIGH

Apollo Router Improperly Enforces Renamed Access Control Directives

Published November 6, 2025Updated November 7, 2025Source: osv

Summary

# Summary A vulnerability in Apollo Router allowed for unauthorized access to protected data through schema elements with access control directives (`@authenticated`, `@requiresScopes`, and `@policy`) that were renamed via `@link` imports. Router did not enforce renamed access control directives on schema elements (e.g. fields and types), allowing queries to bypass those element-level access controls. ## Details Apollo Federation allows users to specify access control directives (`@authenticated`, `@requiresScopes`, and `@policy`](https://www.apollographql.com/docs/graphos/routing/security/authorization#authorization-directives)) to protect schema data access at the element level. These directives can optionally be renamed via the [`imports` argument to the `@link` directive](https://www.apollographql.com/docs/graphos/schema-design/federated-schemas/reference/directives#renaming-directives), which can be useful if their default names match an existing user-defined directive in their subgraph schema. However, Apollo Router's access control logic ignored the `imports` argument, and would accordingly ignore access control directives that were renamed in this way. ## Who Is Impacted This vulnerability impacts Apollo Router customers defining `@authenticated`, `@requiresScopes`, or `@policy` directives on schema elements that were renamed via `@link` imports are impacted. ### Scope of Impact The vulnerability could allow a malicious actor to craft a query that can bypass access control requirements on schema elements protected by renamed access control directives. ## Patches This vulnerability has been fixed in Apollo Router by updating the access control logic to handle the `imports` argument in `@link` directives. You will need to update Router to one of the following versions: - 1.61.12+ - 2.8.1+ ## Workarounds - If you are not immediately updating Router to a patched version, you should remove any renames of access control directives in the `imports` argument to the `@link` directive. - Customers not using Apollo Router with renamed access control directives (`@authenticated`, `@requiresScopes`, and `@policy`) are not affected and do not need to take action.

Remediation

Upgrade to the fixed version using your package manager.

Cargo
Update apollo-router to 2.8.1 or later
cargo update -p apollo-router --precise 2.8.1
Cargo
Update apollo-router to 1.61.12 or later
cargo update -p apollo-router --precise 1.61.12

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (2)

PackageEcosystemAffectedFixed In
apollo-router
crates.io
All versions2.8.1
apollo-router
crates.io
All versions1.61.12

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Frequently Asked Questions

What is CVE-2025-64347?
Apollo Router Improperly Enforces Renamed Access Control Directives This vulnerability has been assigned a severity rating of HIGH (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2025-64347?
CVE-2025-64347 affects apollo-router. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-64347 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-g8jh-vg5j-4h3f

Related CVEs

  • CVE-2024-32971
    CRITICAL

    Apollo Router vulnerable to Critical Regression In Query Plan Cache

  • CVE-2025-32380
    HIGH

    Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing

  • CVE-2025-32034
    HIGH

    Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion

  • CVE-2025-32033
    HIGH

    Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow

  • CVE-2025-32032
    HIGH

    Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass

  • CVE-2024-28101
    HIGH

    Apollo Router's Compressed Payloads do not respect HTTP Payload Limits

  • CVE-2024-43414
    HIGH

    Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries

  • CVE-2023-45812
    HIGH

    Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies