Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 29 SEP 2026

Api Platform · AUTOMATIC DISCOVERY

API Platform Lifecycle policy

API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

API Platform is tracked by BlackTree as a software framework or development platform. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application development components
  • Versioned runtime or build interfaces
  • Security and compatibility maintenance

Typical use

Used by software teams to build, run or maintain applications.

Deployment

Included in source projects, application dependencies, build systems or managed runtimes.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductAPI Platform
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

No CISA known-exploited entries currently match this mapped product family.

This does not mean the product has no vulnerabilities.

Package vulnerability advisories

Checked 29 Sep 2026

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

CVE-2023-25575High severity

api-platform/core's secured properties may be accessible within collections

pkg:composer/api-platform/coreFixed: 3.0.12, 3.1.3, 2.7.10

OSV record
CVE-2025-31485High severity

GraphQL grant on a property might be cached with different objects

pkg:composer/api-platform/coreFixed: 4.0.22, 3.4.17, 4.1.5

OSV record
CVE-2025-31481High severity

GraphQL query operations security can be bypassed

pkg:composer/api-platform/coreFixed: 4.0.22, 3.4.17, 4.1.5

OSV record
CVE-2026-54164Medium severity

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

pkg:composer/api-platform/coreFixed: 4.1.30, 4.2.26, 4.3.12

OSV record
CVE-2026-49858Medium severity

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

pkg:composer/api-platform/coreFixed: 4.1.29, 4.2.25, 4.3.8

OSV record
CVE-2023-47639Medium severity

API Platform Core can leak exceptions message that may contain sensitive information

pkg:composer/api-platform/coreFixed: 3.2.5

OSV record
CVE-2025-23204Medium severity

API Platform Core does not call GraphQl securityAfterResolver

pkg:composer/api-platform/coreFixed: 3.3.15

OSV record
CVE-2019-1000011Medium severity

Incorrect Access Control vulnerability in api-platform/core

pkg:composer/api-platform/coreFixed: 2.2.10, 2.3.6

OSV record

Source evidence

PRIMARYManual

API Platform official lifecycle source

Older versions (1.x, 2.6…, 3.0…, 4.0, 4.1) are not maintained . If you still use them, you must upgrade as soon as possible. | The old-stable branch is merged in the stable branch on a regular basis to propagate security fixes . The stable branch is merged in the development branch on a regular basis to propagate security and regular bugfixes. | New major versions of API Platform are released every 2 years. New minor versions of API Platform are released every 6 months. | The latest minor version of a major branch contains all the new features introduced in the first version of the next major, but also contains deprecated features which are removed in the next major branch. | You can also help us improve the documentation of this page. | Using an AI coding agent? See the documentation index for LLMs at /docs/llms.txt . | Made with love by

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 29 Sep 2026 · Review state accepted

Open official vendor source