Security: apollographql/apollo-server
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) preventionGHSA-9q82-xgwf-vj6h published
Mar 24, 2026 by glasserModerate -
Denial of service with `startStandaloneServer`GHSA-mp6q-xf9x-fwf7 published
Feb 4, 2026 by phryneasHigh -
CSRF via window.postMessage origin-validation bypass in Apollo Embedded Sandbox and ExplorerGHSA-47qc-hrx3-r993 published
Sep 25, 2025 by glasserHigh -
Prevent logging invalid header valuesGHSA-j5g3-5c8r-7qfx published
Aug 30, 2023 by trevor-scheerLow -
Unsafe application of Content Security Policy via reused noncesGHSA-68jh-rf6x-836f published
Jun 15, 2023 by trevor-scheerLow -
Batched HTTP requests may set incorrect `cache-control` response headerGHSA-8r69-3cvp-wxc3 published
Nov 2, 2022 by glasserModerate -
URL-based XSS attack affecting IE11 on default landing pageGHSA-2fvv-qxrq-7jq6 published
Aug 10, 2022 by glasserLow -
The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutationsGHSA-2p3c-p3qw-69r4 published
May 25, 2022 by glasserModerate -
Cross-site Scripting Vulnerability in GraphQL Playground (distributed by Apollo Server)GHSA-qm7x-rc44-rrqw published
Nov 4, 2021 by glasserHigh -
Schema validation rules are not passed to the subscription server, including rules that restrict introspectionGHSA-w42g-7vfc-xf37 published
Jun 4, 2020 by abernixModerate