CVE-2026-32621Disclosure

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they may be able to pollute Object.prototype in gateway by crafting JSON response payloads that target prototype-inheritable properties. This vulnerability is fixed in 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-13); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-13: 2Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 103-1303-1603-1703-20
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure2
2026-03-161
Patch1
2026-03-171
Patch1
2026-03-201
Disclosure1
Full discourse5 posts
  • maruomosquit@maru1151157
    Patch

    🚨 CVE-2026-32621 (CVSS: 9.9) Apache Apollo Federation 2.xのバージョン2.9.6以前などで、クエリ実行時にObject.prototype汚染が可能。悪意のあるクライアントやサブグラフがJSONレスポンスでプロトタイププロパティを操作可能。2.9.6以降で修正。 https://maruomosquit.com/vulnerability/CVE-2026-32621/ #脆弱性 #セキュリティ

    Post summary

    The post discloses a prototype‑pollution vulnerability in Apache Apollo Federation, notes its CVSS score and affected versions, and indicates that it has been patched in version 2.9.6 or later.

    0001078
    2.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Apollo Federation` is affected by CVE-2026-32621, a prototype pollution flaw due to incomplete key sanitization. Potential for property injection exists. Monitor for updates. #GraphQL #Security #AppSec https://www.pulsepatch.io/posts/cve-2026-32621-apollo-federation-prototype-pollution

    Post summary

    The post announces a prototype pollution vulnerability (CVE-2026-32621) in Apollo Federation, highlighting its nature and advising users to monitor for updates.

    0000039
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32621: CRITICAL] Vulnerability in Apollo Federation before versions 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2 allows pollution of Object.prototype, posing a risk to cyber security. Update now!#cve,CVE-2026-32621,#cybersecurity https://cvefind.com/CVE-2026-32621

    Post summary

    The post announces a critical prototype‑pollution flaw in older Apollo Federation releases and urges users to apply the available patch by updating.

    0000047
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32621 Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2, a vulnerability exists… https://www.cve.org/CVERecord?id=CVE-2026-32621

    Post summary

    The post reports CVE‑2026‑32621, noting it affects older Apollo Federation versions and is resolved in newer releases, but provides no PoC, exploit, or detailed technical data.

    00000151
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32621: Apollo Federation has prototype ... Prototype pollution through GraphQL field aliases hitting Object.prototype - every federated Apollo gateway becomes a J... https://zerodaysignal.com/vulnerability/CVE-2026-32621 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a prototype pollution vulnerability in Apollo Federation (CVE-2026-32621) involving GraphQL field aliases that hit Object.prototype, but offers no PoC, exploit, or patch.

    0000058
    147 followersView on X

Explore more