apollo-router is vulnerable to Denial of Service (DoS)
75
High Risk
The Apollo Router query planner enters unbounded recursion when an operation contains two nested @defer inline fragments that share an identical label value. Processing such an operation causes a stack overflow that abnormally terminates the router process. Any party able to submit a GraphQL operation with @defer support enabled can trigger the condition without authentication, disrupting availability for the affected instance until it recovers. The fix rejects operations that reuse a @defer label so that labels are unique within an operation.
You are affected if you are using a version that falls within the vulnerable range and you have @defer support enabled (the default unless supergraph.defer_support is set to false).
apollo-router is vulnerable to Denial of Service (DoS) in versions 1.8.0 - 2.10.4 and 2.11.0 - 2.16.0.
Upgrade the apollo-router library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant