Description
We encourage all users of Apollo Server to read this advisory in its entirety to understand the impact. The Resolution section contains details on patched versions.
Recommendation
Update the apollo-server-cloudflare package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.14.2
- Patched version(s): 2.14.2
References
Could your website be exposed too?
SmartScanner can check your website for Introspection in schema validation in Apollo Server and gives you actionable findings to investigate.
Start a free scanRelated Issues
- angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend - CVE-2023-28444
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions - CVE-2026-42190
- lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability - CVE-2024-32964
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


