Api Platform · AUTOMATIC DISCOVERY
API Platform Lifecycle policy
API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.
Product overview
API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Application development components
- Versioned runtime or build interfaces
- Security and compatibility maintenance
Typical use
Used by software teams to build, run or maintain applications.
Deployment
Included in source projects, application dependencies, build systems or managed runtimes.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
Collected lifecycle data
| Product | API Platform |
|---|---|
| Release | Lifecycle policy |
| Start or release | Not extracted |
| Lifecycle boundary | Continuous or not dated in the source |
| Date precision | Unknown |
Known exploited vulnerabilities
Catalogue updated 1 Oct 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
No CISA known-exploited entries currently match this mapped product family.
This does not mean the product has no vulnerabilities.
Package vulnerability advisories
Checked 29 Sep 2026OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
GraphQL grant on a property might be cached with different objects
OSV recordGraphQL query operations security can be bypassed
OSV recordAPI Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
OSV recordAPI Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
OSV recordAPI Platform Core can leak exceptions message that may contain sensitive information
OSV recordAPI Platform Core does not call GraphQl securityAfterResolver
OSV recordIncorrect Access Control vulnerability in api-platform/core
OSV recordSource evidence
API Platform official lifecycle source
Older versions (1.x, 2.6…, 3.0…, 4.0, 4.1) are not maintained . If you still use them, you must upgrade as soon as possible. | The old-stable branch is merged in the stable branch on a regular basis to propagate security fixes . The stable branch is merged in the development branch on a regular basis to propagate security and regular bugfixes. | New major versions of API Platform are released every 2 years. New minor versions of API Platform are released every 6 months. | The latest minor version of a major branch contains all the new features introduced in the first version of the next major, but also contains deprecated features which are removed in the next major branch. | You can also help us improve the documentation of this page. | Using an AI coding agent? See the documentation index for LLMs at /docs/llms.txt . | Made with love by
Publisher identity used by product-specific official-source collectors.
Open official vendor source