CVE Feed

    Dashboard / CVE / CVE-2026-32621

    CVE-2026-32621

    Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

    Published:Mar 13, 2026
    Last Modified:Mar 23, 2026
    EPS:Mar 13, 2026
    EPSS Score:0.00032
    CVSS Score:9.9

    Affected Products

    Vendor
    Apollographql
    Product
    Federation-internals
    Vendor
    Apollographql
    Product
    Gateway
    Vendor
    Apollographql
    Product
    Query-planner

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High