Junglewise Threat Intelligence

CVE-2025-64530: Apollo composition access control bypass on interface types and fields

CVE-2025-64530 · Severity: low · CVSS 3.1 · Published 2025-11-14

Vendors: Apollo.

Executive brief

Apollo Federation is a system that combines multiple GraphQL services into a unified API. This vulnerability allows attackers to bypass access control policies by querying implementing object types instead of protected interface types, potentially exposing data that should have been restricted. Organizations using Apollo Router with access control directives on interface types are at risk of unauthorized data exposure.

Technical details

The vulnerability is an improper access control enforcement (CWE-284, CWE-288) in Apollo Composition's federation logic. Apollo Router enforces access control directives (@authenticated, @requiresScopes, @policy) on object and interface types/fields, but the GraphQL specification does not define directive inheritance rules. An attacker can bypass interface-level access controls by crafting queries using inline or named fragments to query the implementing object types/fields directly, which do not inherit the interface's access control requirements. The vulnerability affects all versions prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1. The fix rejects user-defined access control directives on interface types/fields and automatically generates them for implementations.

Affected products

  • Apollo composition before 2.9.5, 2.10.0-alpha.3 to before 2.10.4, 2.11.0 to before 2.11.5, 2.12.0 to before 2.12.1

Timeline

  • 2025-11-13: disclosed: Vulnerability published on NVD
  • 2025-11-14: advisory: GitHub security advisory published
  • 2025-11-14: patched: Fixed in versions 2.9.5, 2.10.4, 2.11.5, 2.12.1

References