Junglewise Threat Intelligence

Apollo Server XS-Search bypass via browser CORS bug

Severity: medium · CVSS 4 · Published 2026-03-26

Technologies: apollo-server-core (npm), apollo-server (npm). Vendors: npm, Apollo.

Executive brief

Apollo Server is a popular GraphQL API server that includes built-in protections against Cross-Site Request Forgery (CSRF) and timing-based attacks. A bug in a major web browser's implementation of the CORS security standard allows attackers to bypass these protections and perform XS-Search attacks—measuring response times to infer sensitive information like whether specific fields are null or how many items are in a list. This affects servers that use cookie-based authentication, potentially exposing information about user data or system state without triggering visible side effects.

Technical details

This vulnerability exploits a CORS compliance bug in a major browser (introduced in 2025, planned fix in May 2026) that fails to enforce the Cross-Origin Resource Sharing specification. Apollo Server implements CSRF/XS-Search prevention by rejecting GraphQL requests lacking proper CORS preflight, but the browser bug allows certain specially crafted HTTP GET requests with non-standard Content-Type headers to bypass this protection. The attack is network-based, requires the victim to visit attacker-controlled content while authenticated to a GraphQL server using cookies or HTTP Basic Auth, and allows timing-based analysis of response latencies to infer facts about query results without causing mutations. The vulnerability is patched in @apollo/server v5.5.0 by rejecting GET requests with Content-Type headers other than application/json; apollo-server-core has no patched version as it is end-of-life.

Affected products

  • Apollo Server <5.5.0
  • Apollo apollo-server-core all versions

Timeline

  • 2026-03-26: disclosed: GHSA-9q82-xgwf-vj6h published
  • 2026-03-26: patched: @apollo/server v5.5.0 released
  • 2025: other: Browser vendor introduced CORS compliance bug
  • 2026-05: other: Browser vendor plans to ship fix

References

Related threats