CVE-2025-64347 - CVE House
Back to Database
Status published High CVE-2025-64347

Apollo Router Improperly Enforces Renamed Access Control Directives

Vulnerability Description

Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. Versions 1.61.12-rc.0 and below and 2.8.1-rc.0 allow unauthorized access to protected data through schema elements with access control directives (@authenticated, @requiresScopes, and @policy) that were renamed via @link imports. Router did not enforce renamed access control directives on schema elements (e.g. fields and types), allowing queries to bypass those element-level access controls. This issue is fixed in versions 1.61.12 and 2.8.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64347

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

apollographql

View all reports →

Affected Software

router
Vulnerable Versions:
< 1.61.12, >= 2.8.1-rc.0, < 2.8.1

Timeline

Official Publish: November 7th, 2025
Last Modified: November 7th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)