5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether @apollo/gateway is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.9
CVE-2026-32621
Apollo Federation vulnerable to prototype pollution via incomplete key sanitization
HIGH 7.5
CVE-2025-32030
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Named Fragment Expansion
HIGH 7.5
CVE-2025-32031
Apollo Gateway Query Planner Vulnerable to Excessive Resource Consumption via Optimization Bypass
HIGH 7.5
CVE-2024-43414
Apollo Query Planner and Apollo Gateway may infinitely loop on sufficiently complex queries
HIGH 7.3
GHSA-74cr-77xc-8g6r
Prototype Pollution in @apollo/gateway
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes