CVE-2026-49858
- EPSS 0.21%
- Veröffentlicht 01.07.2026 19:24:58
- Zuletzt bearbeitet 02.07.2026 18:41:35
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing isCacheKeySafe gate in the JSON:API and HAL item normalizers causes a cross-user attribute leak. #...
CVE-2026-54164
- EPSS 0.2%
- Veröffentlicht 01.07.2026 19:14:28
- Zuletzt bearbeitet 02.07.2026 17:54:15
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does not validate the resource type returned when resolving relation IRIs, allowi...
CVE-2025-31485
- EPSS 0.57%
- Veröffentlicht 03.04.2025 19:31:46
- Zuletzt bearbeitet 15.04.2026 00:35:42
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() met...
CVE-2025-31481
- EPSS 0.44%
- Veröffentlicht 03.04.2025 19:20:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.
CVE-2023-47639
- EPSS 0.36%
- Veröffentlicht 03.04.2025 17:15:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.
CVE-2025-23204
- EPSS 0.29%
- Veröffentlicht 24.03.2025 15:53:19
- Zuletzt bearbeitet 15.04.2026 00:35:42
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As this falls bac...
CVE-2023-25575
- EPSS 0.6%
- Veröffentlicht 28.02.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 07:49:45
API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The problem aff...
CVE-2019-1000011
- EPSS 1.02%
- Veröffentlicht 04.02.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:40
API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitable via the u...