CVE-2025-64347
HIGHCrates.io Apollo-router < 1.61.12 - Improper Access Control
Title source: ruleDescription
Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that were renamed via @link imports. Router did not enforce renamed access control directives on schema elements (e.g. fields and types), allowing queries to bypass those element-level access controls. This issue is fixed in versions 1.61.12 and 2.8.1.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/apollographql/router/security/advisories/GHSA-g8jh-vg5j-4h3f
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
17.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (3)
apollographql/router
< 1.61.12
apollographql/router
>= 2.8.1-rc.0, < 2.8.1
crates.io/apollo-router
0 - 1.61.12crates.io
Published
Nov 07, 2025
Tracked Since
Feb 18, 2026