๐Ÿ” CVE Alert

CVE-2026-32621

CRITICAL 9.9

Apollo Federation has prototype pollution via incomplete key sanitization

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
0th

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

CWE CWE-1321
Vendor @apollo
Product federation-internals
Published Mar 13, 2026
Last Updated Mar 16, 2026
Stay Ahead of the Next One

Get instant alerts for @apollo federation-internals

Be the first to know when new critical vulnerabilities affecting @apollo federation-internals are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

@apollo / federation-internals
>= 2.13.0-preview.0, < 2.13.2 >= 2.12.0-preview.0, < 2.12.3 >= 2.11.0-preview.0, < 2.11.6 >= 2.10.0-alpha.0, < 2.10.5 < 2.9.6
@apollo / gateway
>= 2.13.0-preview.0, < 2.13.2 >= 2.12.0-preview.0, < 2.12.3 >= 2.11.0-preview.0, < 2.11.6 >= 2.10.0-alpha.0, < 2.10.5 < 2.9.6
@apollo / query-planner
>= 2.13.0-preview.0, < 2.13.2 >= 2.12.0-preview.0, < 2.12.3 >= 2.11.0-preview.0, < 2.11.6 >= 2.10.0-alpha.0, < 2.10.5 < 2.9.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/apollographql/federation/security/advisories/GHSA-pfjj-6f4p-rvmh