@apollo/gateway
cpe:2.3:a:apollographql:apollo_gateway:*:*:*:*:node.js:*:*
- < 2.10.1
A denial-of-service vulnerability has been identified in Apollo Gateway versions prior to 2.10.1. This issue arises from the query planning process, where deeply nested and reused named fragments are expanded multiple times, leading to exponential resource consumption. As a result, certain query patterns can cause excessive resource usage, rendering the gateway inoperable.
Exploitation of this vulnerability can lead to excessive resource consumption, causing the Apollo Gateway to become inoperable.
Users can upgrade to Apollo Gateway version 2.10.1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.