Apollo GraphQL maintains a focused set of developer tools centered on its GraphQL router, gateway, and client libraries that integrate into API and data-layer architectures. The recurring vulnerability signal reflects the complexity of parsing and resource management in GraphQL protocol handling, with weakness classes including unbounded resource allocation, improper exception handling, data amplification through compression, and cross-site scripting in client contexts. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Apollographql over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35577HIGH Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on | Apr 9, 2026 | 8.1 | 25 | NO | NO |
CVE-2026-23897HIGH Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apollo Client. In versions from 2.0.0 to 3.13.0, 4.2.0 to before | Feb 4, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-43783HIGH The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router | Aug 27, 2024 | 7.5 | 23 | NO | NO |
CVE-2024-43414HIGH Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver aut | Aug 27, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-45812HIGH The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Den | Oct 18, 2023 | 7.5 | 23 | NO | NO |
CVE-2025-32030HIGH Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries wi | Apr 7, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-28101HIGH The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) | Mar 21, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-32031HIGH Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to 2.10.1, a vulnerability in Apollo Gateway allowed queries wi | Apr 7, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-41317MEDIUM The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a D | Sep 5, 2023 | 5.9 | 19 | NO | NO |
CVE-2024-23841MEDIUM apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vuln | Jan 30, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Apollographql.
Media articles that mention a CVE ID that affects a product developed by Apollographql — matched by CVE ID, not by vendor name.