apollo-server-core@3.0.0-rc.1 vulnerabilities

Core engine for Apollo GraphQL server

  • latest version

    3.13.0

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    1 years ago

  • deprecated

    Package is deprecated

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the apollo-server-core package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    apollo-server-core is a core module of the Apollo community GraphQL Server.

    Affected versions of this package are vulnerable to Denial of Service (DoS) by accepting an unbounded amount of memory in the cache.

    NOTE: The size of a cache can be limited with the cache: "bounded" option as of version 3.9.0.

    How to fix Denial of Service (DoS)?

    Upgrade apollo-server-core to version 3.9.0 or higher.

    <3.9.0