An open index of dependabot pull requests across open source projects.

@apollo/server

Ecosystem:
npm
Package URL:
pkg:npm/@apollo/server
Total PRs:
384 Dependabot PRs
Latest PR:
12 days ago
Unique Repositories:
161 repositories
Unique Repos (30 days):
12 repositories
Security Advisories
Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`
GHSA-mp6q-xf9x-fwf7 CVE-2026-23897 HIGH published 4 months ago • updated about 11 hours ago
### Impact The default configuration of `startStandaloneServer` from `@apollo/server/standalone` is vulnerable to Denial of Service (DoS) attacks ...
Batched HTTP requests may set incorrect `cache-control` response header
GHSA-8r69-3cvp-wxc3 MODERATE published over 3 years ago • updated 11 days ago
### Impact In Apollo Server 3 and 4, the `cache-control` HTTP response header may not reflect the cache policy that should apply to an HTTP request...
Prevent logging invalid header values
GHSA-j5g3-5c8r-7qfx LOW published over 2 years ago • updated 2 days ago
## Impact ### What kind of vulnerability is it? Apollo Server can log sensitive information (Studio API keys) if they are passed incorrectly (with ...
@apollo/server vulnerable to unsafe application of Content Security Policy via reused nonces
GHSA-68jh-rf6x-836f LOW published almost 3 years ago • updated 22 days ago
### Context Content Security Policies (CSP) are a defense-in-depth strategy against XSS attacks. Improper application of CSP isn't itself a vulnera...
Apollo Server: Browser bug allows for bypass of XS-Search (read-only Cross-Site Request Forgery) prevention
GHSA-9q82-xgwf-vj6h MODERATE published 2 months ago • updated 23 days ago
# Impact In a Cross-Site Request Forgery attack, untrusted web content causes browsers to send authenticated requests to web servers which use coo...
Recent PRs
Package Details
Name: @apollo/server
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/@apollo/server
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 1
MODERATE 2
LOW 2
View All npm Advisories
Package Information
Description:

Core engine for Apollo GraphQL server

Repository: https://github.com/apollographql/apollo-server
Homepage: https://github.com/apollographql/apollo-server#readme
Latest Release: 4.12.2
12 months ago
Dependent Repos: 5,993
Dependent Packages: 392
Downloads: 5,424,182
Ranking: Top 0.3029% by dependent repos Top 0.1646% by downloads Top 0.1585% by dependent pkgs
PR Status
Open 188 (49.0%)
Merged 28 (7.3%)
Closed 132 (34.4%)
PR Types
Major 135 (35.2%)
Minor 150 (39.1%)
Patch 63 (16.4%)