CVE-2025-64530
Last modified
CVE-2025-64530 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions of Apollo Federation's composition logic prior to 2.9.5, 2.10.4, 2.11.5, and 2.12.1 allowed some queries to Apollo Router to improperly bypass access controls on types/fields. Apollo Federation incorrectly allowed user-defined access control directives on interface types/fields, which could be bypassed by instead querying the implementing object types/fields in Apollo Router via inline fragments, for example. A fix to versions 2.9.5, 2.10.4, 2.11.5, and 2.12.1 of composition logic in Federation now disallows interfaces types and fields to contain user-defined access control directives. Some workarounds are available. Users of Apollo Rover with an unpatched composition version or are using the Apollo Studio build pipeline with Federation version 2.8 or below should manually copy the access control requirements on interface types/fields to each implementing object type/field where appropriate. Do not remove those access control requirements from the interface types/fields, as unpatched Apollo Composition will not automatically generate them in the supergraph schema. Customers not using Apollo Router access control features (`@authenticated`, `@requiresScopes`, or `@policy` directives) or not specifying access control requirements on interface types/fields are not affected and do not need to take action.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-64530?
How severe is CVE-2025-64530?
How do I fix CVE-2025-64530?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64525Astro is a web framework. In Astro versions 2.16.0 up to but…6.5
- CVE-2025-64526Strapi is an open source headless content management system.…5.3
- CVE-2025-64527Envoy is a high-performance edge/middle/service proxy. In 1.…6.5
- CVE-2025-64528Discourse is an open source discussion platform. Prior to ve…5.3
- CVE-2025-64529SpiceDB is an open source database system for creating and m…6.5
- CVE-2025-6453A vulnerability classified as critical has been found in diy…4.3
- CVE-2025-64531Substance3D - Stager versions 3.1.5 and earlier are affected…7.8
- CVE-2025-64537Adobe Experience Manager versions 6.5.23 and earlier are aff…9.3
- CVE-2025-64538Adobe Experience Manager versions 6.5.23 and earlier are aff…9.3
- CVE-2025-64539Adobe Experience Manager versions 6.5.23 and earlier are aff…9.3
- CVE-2025-6454An issue has been discovered in GitLab CE/EE affecting all v…8.8
- CVE-2025-64541Adobe Experience Manager versions 6.5.23 and earlier are aff…5.4
Are you affected by CVE-2025-64530?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
