Loading...
Skip to main content
crates.io (Rust)

apollo-router Security Analysis

apollo-router has 11 known security vulnerabilities in crates.io (Rust). Upgrade to version 2.8.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

11 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 2.8.1

Upgrading to 2.8.1 or later resolves all 11 known vulnerabilities in apollo-router. Update Cargo.toml: apollo-router = "2.8.1"

Is apollo-router in your project?

Check if you're affected and upgrade to 2.8.1 to stay secure.

11
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

11 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2024-32971
Apollo Router vulnerable to Critical Regression In Query Plan Cache
CRITICAL
All versions1.45.1
CVE-2025-64173
Apollo Router Affected by an Access Control Bypass on Polymorphic Types
HIGH
All versions1.61.12, 2.8.1
CVE-2025-64347
Apollo Router Improperly Enforces Renamed Access Control Directives
HIGH
All versions1.61.12, 2.8.1
CVE-2025-32380
Apollo Router Query Validation Vulnerable to Excessive Resource Consumption via Named Fragment Processing
HIGH
All versions1.61.2, 2.1.1
CVE-2025-32033
Apollo Router Operation Limits Vulnerable to Bypass via Integer Overflow
HIGH
All versions1.61.2, 2.1.1
CVE-2025-32034
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
HIGH
All versions1.61.2, 2.1.1
CVE-2025-32032
Apollo Router Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
HIGH
All versions1.61.2, 2.1.1
CVE-2024-43783
Apollo Router Coprocessors may cause Denial-of-Service when handling request bodies
HIGH
All versions1.52.1
CVE-2024-43414
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries
HIGH
All versions1.52.1
CVE-2024-28101
Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
HIGH
All versions1.40.2
CVE-2023-45812
Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions
HIGH
All versions1.33.0

About This Data

Vulnerability data for apollo-router is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related crates.io (Rust) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of apollo-router.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed