{"api_version":"v1","generated_at":"2026-10-09T09:00:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-apollographql-router-1b8f6681613b","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/router","name":"router","next_cursor":null,"observations":[{"affected":"< 1.61.12; >= 2.8.1-rc.0, < 2.8.1","affected_versions_present":true,"cve_id":"CVE-2025-64347","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64347","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-07T18:25:59.775Z","patch_url":"","primary_source":"","published":"2025-11-07T17:47:28.360Z"},{"affected":"< 1.61.12; >= 2.8.1-rc.0, < 2.8.1","affected_versions_present":true,"cve_id":"CVE-2025-64173","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64173","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-07T13:48:35.506Z","patch_url":"","primary_source":"","published":"2025-11-06T20:42:51.785Z"},{"affected":"< 1.61.2; >= 2.0.0-alpha.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2025-32380","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32380","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-09T20:43:06.645Z","patch_url":"","primary_source":"","published":"2025-04-09T16:05:45.994Z"},{"affected":"< 1.61.2; >= 2.0.0-alpha.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2025-32034","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32034","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-08T13:30:44.951Z","patch_url":"","primary_source":"","published":"2025-04-07T20:50:29.690Z"},{"affected":"< 1.61.2; >= 2.0.0-alpha.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2025-32033","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32033","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-08T13:31:44.219Z","patch_url":"","primary_source":"","published":"2025-04-07T20:48:19.504Z"},{"affected":"< 1.61.2; >= 2.0.0-alpha.0, < 2.1.1","affected_versions_present":true,"cve_id":"CVE-2025-32032","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32032","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-08T14:52:25.565Z","patch_url":"","primary_source":"","published":"2025-04-07T20:44:30.050Z"},{"affected":">=1.7.0, < 1.52.1","affected_versions_present":true,"cve_id":"CVE-2024-43783","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-43783","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-27T18:06:45.142Z","patch_url":"https://github.com/apollographql/router/commit/7a9c020608a62dcaa306b72ed0f6980f15923b14","primary_source":"","published":"2024-08-27T17:16:28.571Z"},{"affected":">=1.44.0, <1.45.1","affected_versions_present":true,"cve_id":"CVE-2024-32971","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32971","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T02:27:52.865Z","patch_url":"","primary_source":"","published":"2024-05-02T06:43:27.646Z"},{"affected":">= 0.9.5, < 1.40.2","affected_versions_present":true,"cve_id":"CVE-2024-28101","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-28101","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-05T16:57:05.215Z","patch_url":"https://github.com/apollographql/router/commit/9e9527c73c8f34fc8438b09066163cd42520f413","primary_source":"","published":"2024-03-06T21:07:36.476Z"},{"affected":">= 1.31.0, < 1.33.0","affected_versions_present":true,"cve_id":"CVE-2023-45812","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-45812","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-13T15:02:17.414Z","patch_url":"https://github.com/apollographql/router/pull/4014","primary_source":"","published":"2023-10-18T21:29:32.731Z"},{"affected":">= 1.28.0, < 1.29.1","affected_versions_present":true,"cve_id":"CVE-2023-41317","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-41317","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-30T19:17:12.220Z","patch_url":"https://github.com/apollographql/router/commit/b295c103dd86c57c848397d32e8094edfa8502aa","primary_source":"","published":"2023-09-05T18:31:43.185Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"apollographql"}}
