{"schema_version":1,"title":"Apollo vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in Apollo: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, Apollo Server XS-Search bypass via browser CORS bug, was published on 26 March 2026.","url":"https://junglewise.ai/threats/vendors/apollo","json_url":"https://junglewise.ai/threats/vendors/apollo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/apollo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":4},"latest":[{"cvss":4,"slug":"apollo-server-xs-search-bypass-via-browser-cors-bug-108494ad","title":"Apollo Server XS-Search bypass via browser CORS bug","severity":"medium","exploited":false,"published_at":"2026-03-26T21:53:10+00:00","url":"https://junglewise.ai/threats/apollo-server-xs-search-bypass-via-browser-cors-bug-108494ad"},{"cve":"CVE-2026-32621","cvss":3.1,"epss":0.0056,"slug":"cve-2026-32621-apollo-federation-prototype-pollution-via-incomplete-key","title":"Apollo Federation prototype pollution via incomplete key sanitization","severity":"low","exploited":false,"published_at":"2026-03-13T20:51:10+00:00","url":"https://junglewise.ai/threats/cve-2026-32621-apollo-federation-prototype-pollution-via-incomplete-key"},{"cve":"CVE-2025-64530","cvss":3.1,"epss":0.0038,"slug":"cve-2025-64530-apollo-composition-access-control-bypass-on-interface-types-and","title":"Apollo composition access control bypass on interface types and fields","severity":"low","exploited":false,"published_at":"2025-11-14T17:46:55+00:00","url":"https://junglewise.ai/threats/cve-2025-64530-apollo-composition-access-control-bypass-on-interface-types-and"},{"cve":"CVE-2025-59845","cvss":3.1,"epss":0.0016,"slug":"cve-2025-59845-apollo-embedded-sandbox-and-explorer-csrf-via-postmessage-origin","title":"Apollo Embedded Sandbox and Explorer CSRF via postMessage origin-validation bypass","severity":"low","exploited":false,"published_at":"2025-09-26T15:00:05+00:00","url":"https://junglewise.ai/threats/cve-2025-59845-apollo-embedded-sandbox-and-explorer-csrf-via-postmessage-origin"},{"cve":"CVE-2024-43414","cvss":3.1,"epss":0.0099,"slug":"cve-2024-43414-apollo-query-planner-infinite-loop-on-complex-queries","title":"Apollo Query Planner infinite loop on complex queries","severity":"low","exploited":false,"published_at":"2024-08-27T18:14:12+00:00","url":"https://junglewise.ai/threats/cve-2024-43414-apollo-query-planner-infinite-loop-on-complex-queries"},{"cve":"CVE-2024-23841","cvss":3.1,"epss":0.0039,"slug":"cve-2024-23841-apollo-experimental-nextjs-app-support-cross-site-scripting-in","title":"Apollo experimental-nextjs-app-support cross-site scripting in server-side rendering","severity":"low","exploited":false,"published_at":"2024-01-30T20:57:45+00:00","url":"https://junglewise.ai/threats/cve-2024-23841-apollo-experimental-nextjs-app-support-cross-site-scripting-in"},{"slug":"apollo-apollo-server-improper-csp-via-nonce-reuse-81a87dc6","title":"Apollo apollo-server improper CSP via nonce reuse","severity":"info","exploited":false,"published_at":"2023-06-16T19:40:53+00:00","url":"https://junglewise.ai/threats/apollo-apollo-server-improper-csp-via-nonce-reuse-81a87dc6"},{"slug":"apollo-server-incorrect-cache-control-header-in-batched-requests-d59ff0b9","title":"Apollo Server incorrect cache-control header in batched requests","severity":"info","exploited":false,"published_at":"2022-11-02T18:18:10+00:00","url":"https://junglewise.ai/threats/apollo-server-incorrect-cache-control-header-in-batched-requests-d59ff0b9"},{"cvss":3.1,"slug":"apollo-gateway-prototype-pollution-via-deepmerge-d1328d9d","title":"Apollo Gateway prototype pollution via deepMerge","severity":"low","exploited":false,"published_at":"2019-06-13T20:37:39+00:00","url":"https://junglewise.ai/threats/apollo-gateway-prototype-pollution-via-deepmerge-d1328d9d"}],"vendor":{"hub":true,"name":"Apollo","slug":"apollo","description":"Apollo is a GraphQL client and server platform for building data-driven applications.","url":"https://junglewise.ai/threats/vendors/apollo"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cvss":4,"slug":"apollo-server-xs-search-bypass-via-browser-cors-bug-108494ad","title":"Apollo Server XS-Search bypass via browser CORS bug","severity":"medium","exploited":false,"published_at":"2026-03-26T21:53:10+00:00","url":"https://junglewise.ai/threats/apollo-server-xs-search-bypass-via-browser-cors-bug-108494ad"},{"cve":"CVE-2024-43414","cvss":3.1,"epss":0.0099,"slug":"cve-2024-43414-apollo-query-planner-infinite-loop-on-complex-queries","title":"Apollo Query Planner infinite loop on complex queries","severity":"low","exploited":false,"published_at":"2024-08-27T18:14:12+00:00","url":"https://junglewise.ai/threats/cve-2024-43414-apollo-query-planner-infinite-loop-on-complex-queries"},{"cve":"CVE-2026-32621","cvss":3.1,"epss":0.0056,"slug":"cve-2026-32621-apollo-federation-prototype-pollution-via-incomplete-key","title":"Apollo Federation prototype pollution via incomplete key sanitization","severity":"low","exploited":false,"published_at":"2026-03-13T20:51:10+00:00","url":"https://junglewise.ai/threats/cve-2026-32621-apollo-federation-prototype-pollution-via-incomplete-key"},{"cve":"CVE-2024-23841","cvss":3.1,"epss":0.0039,"slug":"cve-2024-23841-apollo-experimental-nextjs-app-support-cross-site-scripting-in","title":"Apollo experimental-nextjs-app-support cross-site scripting in server-side rendering","severity":"low","exploited":false,"published_at":"2024-01-30T20:57:45+00:00","url":"https://junglewise.ai/threats/cve-2024-23841-apollo-experimental-nextjs-app-support-cross-site-scripting-in"},{"cve":"CVE-2025-64530","cvss":3.1,"epss":0.0038,"slug":"cve-2025-64530-apollo-composition-access-control-bypass-on-interface-types-and","title":"Apollo composition access control bypass on interface types and fields","severity":"low","exploited":false,"published_at":"2025-11-14T17:46:55+00:00","url":"https://junglewise.ai/threats/cve-2025-64530-apollo-composition-access-control-bypass-on-interface-types-and"},{"cve":"CVE-2025-59845","cvss":3.1,"epss":0.0016,"slug":"cve-2025-59845-apollo-embedded-sandbox-and-explorer-csrf-via-postmessage-origin","title":"Apollo Embedded Sandbox and Explorer CSRF via postMessage origin-validation bypass","severity":"low","exploited":false,"published_at":"2025-09-26T15:00:05+00:00","url":"https://junglewise.ai/threats/cve-2025-59845-apollo-embedded-sandbox-and-explorer-csrf-via-postmessage-origin"},{"cvss":3.1,"slug":"apollo-gateway-prototype-pollution-via-deepmerge-d1328d9d","title":"Apollo Gateway prototype pollution via deepMerge","severity":"low","exploited":false,"published_at":"2019-06-13T20:37:39+00:00","url":"https://junglewise.ai/threats/apollo-gateway-prototype-pollution-via-deepmerge-d1328d9d"},{"slug":"apollo-apollo-server-improper-csp-via-nonce-reuse-81a87dc6","title":"Apollo apollo-server improper CSP via nonce reuse","severity":"info","exploited":false,"published_at":"2023-06-16T19:40:53+00:00","url":"https://junglewise.ai/threats/apollo-apollo-server-improper-csp-via-nonce-reuse-81a87dc6"},{"slug":"apollo-server-incorrect-cache-control-header-in-batched-requests-d59ff0b9","title":"Apollo Server incorrect cache-control header in batched requests","severity":"info","exploited":false,"published_at":"2022-11-02T18:18:10+00:00","url":"https://junglewise.ai/threats/apollo-server-incorrect-cache-control-header-in-batched-requests-d59ff0b9"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[]}