@apollo/server is vulnerable to Information Disclosure
40
Medium Risk
Affected versions of the package disclose information by allowing "fuzzy testing" of a graph, either manually or using automated tools, to infer the shape of the schema. This occurs due to the default behavior where a misspelled field in an operation triggers a validation error that includes a helpful "did you mean" suggestion in the error message.
You are affected if you are using a version that falls within the vulnerable range.
@apollo/server is vulnerable to Information Disclosure in versions 1.0.0 - 4.10.5.
Upgrade the @apollo/server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant