Denial of Service Risk in Apollo Gateway by Apollo GraphQL
CVE-2025-32030
7.5HIGH
What is CVE-2025-32030?
Apollo Gateway, a utility for merging multiple GraphQL microservices into a seamless endpoint, has a vulnerability that could cause significant resource consumption. Versions prior to 2.10.1 allow for queries that utilize deeply nested and reused named fragments to lead to excessive query planning costs. This results from named fragments being expanded multiple times during query planning, creating a scenario where resource usage grows exponentially. This flaw can compromise system availability by potentially triggering denial of service conditions.
Affected Version(s)
federation < 2.10.1
