Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
api-platform/core's secured properties may be accessible within collections High
CVE-2023-25575 was published for api-platform/core (Composer) Feb 28, 2023
Toflar Credited to Toflar and soyuka soyuka soyuka
API Platform Core does not call GraphQl securityAfterResolver Moderate
CVE-2025-23204 was published for api-platform/core (Composer) Mar 24, 2025
soyuka Credited to soyuka, vinceAmstoutz, and ausi vinceAmstoutz vinceAmstoutz
ausi ausi
GraphQL query operations security can be bypassed High
CVE-2025-31481 was published for api-platform/core (Composer) Apr 4, 2025
soyuka Credited to soyuka, ausi, and alanpoulain ausi ausi
alanpoulain alanpoulain
GraphQL grant on a property might be cached with different objects High
CVE-2025-31485 was published for api-platform/core (Composer) Apr 4, 2025
ausi Credited to ausi, alanpoulain, soyuka, and Fafabian alanpoulain alanpoulain
soyuka soyuka Fafabian Fafabian
tillmon Credited to tillmon and soyuka soyuka soyuka
tonghuaroot Credited to tonghuaroot and soyuka soyuka soyuka
ProTip! Advisories are also available from the GraphQL API