{"api_version":"v1","generated_at":"2026-10-08T21:30:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-apollographql-federation-d3232bfdc370","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/federation","name":"federation","next_cursor":null,"observations":[{"affected":"< 2.9.5; >= 2.10.0-preview.0, < 2.10.4; >= 2.11.0-preview.0, < 2.11.5; >= 2.12.0-preview.0, 2.12.1","affected_versions_present":true,"cve_id":"CVE-2025-64530","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64530","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-14T15:57:42.013Z","patch_url":"","primary_source":"","published":"2025-11-13T23:02:45.740Z"},{"affected":"< 2.10.1","affected_versions_present":true,"cve_id":"CVE-2025-32031","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32031","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-08T14:52:34.948Z","patch_url":"https://github.com/apollographql/federation/pull/3236","primary_source":"","published":"2025-04-07T20:41:35.767Z"},{"affected":"< 2.10.1","affected_versions_present":true,"cve_id":"CVE-2025-32030","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32030","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-08T18:25:01.371Z","patch_url":"https://github.com/apollographql/federation/pull/3236","primary_source":"","published":"2025-04-07T20:38:59.654Z"},{"affected":">= 2.0.0, < 2.8.5; < 1.52.1","affected_versions_present":true,"cve_id":"CVE-2024-43414","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43414","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-27T17:58:38.192Z","patch_url":"","primary_source":"","published":"2024-08-27T17:20:05.375Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"apollographql"}}
