apollo-router is vulnerable to Denial of Service (DoS)
75
High Risk
Apollo Router demand control estimates an operation's cost before execution and rejects operations exceeding a configured maximum when running in enforce mode. A client-supplied negative @listSize slicing argument, or a configured list size exceeding the signed 32-bit integer range, can drive an operation's estimated cost negative. A negative contribution offsets the cost of sibling fields so that an otherwise-expensive operation passes enforcement while the expensive work still executes. The fix clamps negative slicing values to zero and uses a saturating conversion so an estimated cost can no longer be driven below zero.
You are affected if you are using a version that falls within the vulnerable range and you have demand control enabled in enforce mode.
apollo-router is vulnerable to Denial of Service (DoS) in versions 2.0.0 - 2.10.4 and 2.11.0 - 2.16.0.
Upgrade the apollo-router library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant