Description
We encourage all users of Apollo Server to read this advisory in its entirety to understand the impact. The Resolution section contains details on patched versions.
Recommendation
Update the apollo-server-cloudflare package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.14.2
- Patched version(s): 2.14.2
References
Related Issues
- angular-server-side-configuration information disclosure vulnerability in monorepo with node.js backend - CVE-2023-28444
- RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests - CVE-2026-39371
- RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions - CVE-2026-42190
- lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability - CVE-2024-32964
You might also like:
- Tags:
- npm
- apollo-server-cloudflare
Anything's wrong? Let us know Last updated on January 09, 2023


