Memory Leak Vulnerability in GraphQL Federation Framework by Ardatan
CVE-2025-27097

5.1MEDIUM

Key Information:

Vendor

Ardatan

Vendor
CVE Published:
20 February 2025

What is CVE-2025-27097?

The GraphQL Mesh framework, utilized for building GraphQL applications with diverse APIs and databases, is susceptible to a memory leak when handling queries. Specifically, if a user executes a transformation on the root level with varied query variables, the framework continues using the initial set of variables for subsequent requests due to inadequate cache behavior. This flaw allows for potential misuse of sensitive tokens sent through these variables, as the underlying system does not refresh the token appropriately across multiple requests. Consequently, this can lead to unintended access and data exposure until the cache clears through its least recently used (LRU) eviction mechanism.

Affected Version(s)

graphql-mesh @graphql-mesh/runtime: >= 0.96.9, < 0.96.9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.