Vulnerability Database

With exploit

apollo-server-core

Title Severity Exploit Date Affected Version
Prevent logging invalid header values Low Aug 30, 2023 >= 3.0.0 < 3.12.1
< 2.26.1
Batched HTTP requests may set incorrect `cache-control` response header Medium Nov 2, 2022 >= 3.0.0 < 3.11.0
apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page Medium Aug 18, 2022 >= 3.0.0 < 3.10.1
Introspection in schema validation in Apollo Server Medium Jun 5, 2020 < 2.14.2