<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:55:20.854045+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-163104</id>
    <title>EUVD-2026-163104</title>
    <updated>2026-10-09T08:55:20.915651+00:00</updated>
    <content>EUVD-2026-163104</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-163104"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45812</id>
    <title>fkie_cve-2023-45812</title>
    <updated>2026-10-09T08:55:20.915695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses the `@defer` or Subscriptions, the Router will panic. To be vulnerable, users of Router must have a coprocessor with `coprocessor.supergraph.response` configured in their `router.yaml` and also to support either `@defer` or Subscriptions. Apollo Router version 1.33.0 has a fix for this vulnerability which was introduced in PR #4014. Users are advised to upgrade. Users unable to upgrade should avoid using the coprocessor supergraph response or disable defer and subscriptions support and continue to use the coprocessor supergraph response.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-45812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r344-xw3p-2frj</id>
    <title>GHSA-r344-xw3p-2frj — Apollo Router vulnerable to Improper Check or Handling of Exceptional Conditions</title>
    <updated>2026-10-09T08:55:20.915735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: apollo-router</p>
<p>### Impact
The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a multi-part response is sent. When users send queries to the router that uses the `@defer` or Subscriptions, the Router will panic.
 
To be vulnerable, users of Router must have a coprocessor with `coprocessor.supergraph.response` configured in their `router.yaml` and also to support either `@defer` or Subscriptions.</p>
<p>### Patches
Router version 1.33.0 has a fix for this vulnerability. https://github.com/apollographql/router/pull/4014 fixes the issue.</p>
<p>### Workarounds
For affected versions, avoid using the coprocessor supergraph response:
```yml
# do not use this stage in your coprocessor configuration
coprocessor:
  supergraph:
    response:
```</p>
<p>Or you can disable defer and subscriptions support:
```yml
# disable defer and subscriptions:
supergraph:
  defer_support: false # enabled by default
subscription:
  enabled: false # disabled by default
```
and continue to use the coprocessor supergraph response.
### References
https://github.com/apollographql/router/issues/4013</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r344-xw3p-2frj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-45812</id>
    <title>gsd-2023-45812</title>
    <updated>2026-10-09T08:55:20.915773+00:00</updated>
    <content>gsd-2023-45812</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-45812"/>
  </entry>
</feed>
