CVE Database
/

CVE-2026-32621

Back to search

CVE-2026-32621

Published: Mar 13, 2026

Modified: Mar 16, 2026

PUBLISHED

CVSS v3.1

9.9

CRITICAL

Description

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

VendorProductVersions

@apollo

federation-internals

affected
>= 2.13.0-preview.0, < 2.13.2
affected
>= 2.12.0-preview.0, < 2.12.3
affected
>= 2.11.0-preview.0, < 2.11.6
affected
>= 2.10.0-alpha.0, < 2.10.5
affected
< 2.9.6

@apollo

gateway

affected
>= 2.13.0-preview.0, < 2.13.2
affected
>= 2.12.0-preview.0, < 2.12.3
affected
>= 2.11.0-preview.0, < 2.11.6
affected
>= 2.10.0-alpha.0, < 2.10.5
affected
< 2.9.6

@apollo

query-planner

affected
>= 2.13.0-preview.0, < 2.13.2
affected
>= 2.12.0-preview.0, < 2.12.3
affected
>= 2.11.0-preview.0, < 2.11.6
affected
>= 2.10.0-alpha.0, < 2.10.5
affected
< 2.9.6

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now