api-platform/core
Packagist6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting api-platform/corepage 1 of 1
- CVE-2019-1000011MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.3.62019-02-04
vulnerable: v2.3.0 ... v2.3.5 (6 versions)
API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource can delete any resource. This attack appears to be exploitabl…
- CVE-2023-25575HIGHCVSS 7.7EG 7.7✓ Fixed in 2.7.102023-02-28
vulnerable: v2.6.0 ... v2.7.9 (35 versions)
API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiProperty` attribute can be disclosed to unauthorized users. The …
- CVE-2023-47639MEDIUMCVSS 5.3EG 5.3✓ Fixed in 3.2.52025-04-03
vulnerable: v3.2.0, v3.2.1, v3.2.2, v3.2.3, v3.2.4
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON error response. This vulnerability is fixed in 3.2.5.
- CVE-2025-23204MEDIUMCVSS 4.4EG 4.4✓ Fixed in 3.3.152025-03-24
vulnerable: v3.3.10 ... v3.3.9 (7 versions)
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Starting in version 3.3.8, a security check that gets called after GraphQl resolvers is always replaced by another one as there's no break in a clause. As thi…
- CVE-2025-31481HIGHCVSS 7.5EG 7.5✓ Fixed in 4.1.52025-04-03
vulnerable: v4.1.0 ... v4.1.4 (9 versions)
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you can bypass the configured security on an operation. This vulnerability is fixed in 4.0.22 and 3.4.17.
- CVE-2025-31485HIGHCVSS 7.5EG 7.5✓ Fixed in 4.1.52025-04-03
vulnerable: v4.1.0 ... v4.1.4 (9 versions)
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKe…
Check whether api-platform/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for api-platform/core CVEs against the assets you own.
Start Free Scan →