npm package report

Is @apollo/federation-internals safe?

1 known vulnerability, worst severity CRITICAL.

cvss
9.9

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
4.7

CyberXYZ composite, out of 10

fig. 01 — GHSA-pfjj-6f4p-rvmh, the advisory selected below

// advisories

GHSA-pfjj-6f4p-rvmh

CRITICALCVE-2026-32621

A vulnerability exists in query plan execution within the gateway that may allow pollution of Object.prototype in certain scenarios. A malicious client may be able to pollute Object.prototype in gateway directly by crafting operations with field aliases and/or variable names that target prototype-inheritable properties. Alternatively, if a subgraph were to be compromised by a malicious actor, they

Affected
>=0, <2.9.6, >=2.10.0, <2.10.5, >=2.11.0, <2.11.6, >=2.12.0, <2.12.3, >=2.13.0, <2.13.2, >=0, <2.9.6, >=2.10.0, <2.10.5, >=2.11.0, <2.11.6, >=2.12.0, <2.12.3, >=2.13.0, <2.13.2, >=0, <2.9.6, >=2.10.0, <2.10.5, >=2.11.0, <2.11.6, >=2.12.0, <2.12.3, >=2.13.0, <2.13.2, < 2.9.6
Fixed in
2.9.6
Weakness
CWE-1321
Published
2026-03-13
Source
osv

NVDMITREOSV


// dependencies

4 direct, 1 carrying known advisories, worst MEDIUM

Sign in for dependency paths and remediation

// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 03:28 UTC. The most recent advisory here was published 2026-03-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @apollo/federation-internals safe? npm package security report | CyberXYZ