Junglewise Threat Intelligence

CVE-2026-32621: Apollo Federation prototype pollution via incomplete key sanitization

CVE-2026-32621 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: Apollo Gateway. Vendors: Apollo.

Executive brief

Apollo Federation is a JavaScript library for building federated GraphQL APIs. A prototype pollution vulnerability in query plan execution allows attackers to corrupt shared object properties in the Node.js process, potentially leading to privilege escalation, data tampering, or unexpected application behavior affecting all subsequent requests to the gateway.

Technical details

This is a prototype pollution vulnerability (CWE-1321) in Apollo Federation's query plan execution engine caused by incomplete sanitization of GraphQL field aliases and variable names. An authenticated attacker can inject crafted operations targeting prototype-inheritable properties like __proto__, constructor, or prototype. Alternatively, a compromised subgraph can send malicious JSON payloads to pollute Object.prototype in the gateway. Since Object.prototype is shared across the Node.js process, successful exploitation affects all subsequent requests and can result in code execution, privilege escalation, or data integrity violations depending on how polluted properties are consumed by the application or dependencies. Patches are available in @apollo/federation-internals, @apollo/gateway, and @apollo/query-planner versions 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

Affected products

  • Apollo federation-internals all versions before 2.9.6; 2.10.0 before 2.10.5; 2.11.0 before 2.11.6; 2.12.0 before 2.12.3; 2.13.0 before 2.13.2
  • Apollo gateway all versions before 2.9.6; 2.10.0 before 2.10.5; 2.11.0 before 2.11.6; 2.12.0 before 2.12.3; 2.13.0 before 2.13.2
  • Apollo query-planner all versions before 2.9.6; 2.10.0 before 2.10.5; 2.11.0 before 2.11.6; 2.12.0 before 2.12.3; 2.13.0 before 2.13.2

Timeline

  • 2026-03-13: disclosed: GHSA-pfjj-6f4p-rvmh published
  • 2026-03-13: patched: Patches released in versions 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2

References

Related threats