api-platform/core Security Advisories for v2.2.2 (4)
-
[MEDIUM] API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
PKSA-8kfs-m8zw-ggzs CVE-2026-54164 GHSA-9rjg-x2p2-h68h
Affected version: >=4.3.0,<4.3.12|>=4.2.0,<4.2.26|<4.1.30
Reported by:
GitHub -
[HIGH] GraphQL grant on a property might be cached with different objects
PKSA-gs8r-6kz6-pp56 CVE-2025-31485 GHSA-428q-q3vv-3fq3
Affected version: <3.4.17|>=4.0.0,<4.0.22|>=4.1.0,<4.1.5
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[HIGH] GraphQL query operations security can be bypassed
PKSA-gnn4-pxdg-q76m CVE-2025-31481 GHSA-cg3c-245w-728m
Affected version: <3.4.17|>=4.0.0,<4.0.22|>=4.1.0,<4.1.5
Reported by:
FriendsOfPHP/security-advisories, GitHub -
[MEDIUM] CVE-2019-1000011: Access control bypass in GraphQL mutations
PKSA-2j74-htpf-prz8 CVE-2019-1000011 GHSA-974j-wjxx-wggj
Affected version: >=2.2.0,<2.2.10|>=2.3.0,<2.3.6
Reported by:
FriendsOfPHP/security-advisories, GitHub