Memory Leak Vulnerability in GraphQL Federation Framework by Ardatan
CVE-2025-27097
What is CVE-2025-27097?
The GraphQL Mesh framework, utilized for building GraphQL applications with diverse APIs and databases, is susceptible to a memory leak when handling queries. Specifically, if a user executes a transformation on the root level with varied query variables, the framework continues using the initial set of variables for subsequent requests due to inadequate cache behavior. This flaw allows for potential misuse of sensitive tokens sent through these variables, as the underlying system does not refresh the token appropriately across multiple requests. Consequently, this can lead to unintended access and data exposure until the cache clears through its least recently used (LRU) eviction mechanism.
Affected Version(s)
graphql-mesh @graphql-mesh/runtime: >= 0.96.9, < 0.96.9
