CVE-2024-43783: Apollo Router Coprocessors may cause Denial-of-Service when handling request bodies

Published Aug 27, 2024
·
Updated

Impact

Instances of the Apollo Router using either of the following may be impacted by a denial-of-service vulnerability.

1. External Coprocessing with specific configurations; or 2. Native Rust Plugins accessing the Router request body in the RouterService layer

Router customizations using Rhai scripts are not impacted.

When using External Coprocessing:

Instances of the Apollo Router running versions >=1.21.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true:

1. Router has been configured to support External Coprocessing. 2. Router has been configured to send request bodies to coprocessors. This is a non-default configuration and must be configured intentionally by administrators.

You can identify if you are impacted by reviewing your router's configuration YAML for the following config:

yaml ... coprocessor: url: http://localhost:9000 # likely different in your environment router: request: body: true # this must be set to 'true' to be impacted ... External Coprocessing was initially made available as an experimental feature with Router version 1.21.0 on 2023-06-20 and was made generally available with Router version 1.38.0 on 2024-01-19. More information about the Router’s External Coprocessing feature is available here.

When using Native Rust Plugins:

Instances of the Apollo Router running versions >=1.7.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true:

1. Router has been configured to use a custom-developed Native Rust Plugin 2. The plugin accesses Request.routerrequest in the RouterService layer 3. You are accumulating the body from Request.routerrequest into memory

To use a plugin, you need to be running a customized Router binary. Additionally, you need to have a plugins section with at least one plugin defined in your Router’s configuration YAML. That plugin would also need to define a custom routerservice method.

You can check for a defined plugin by reviewing for the following in your Router’s configuration YAML:

yaml ... plugins: custompluginname: # custom config here ...

You can check for a custom routerservice method in a plugin, by reviewing for the following function signature in your plugin’s source:

rust fn routerservice(&self, service: router::BoxService) -> router::BoxService

More information about the Router’s Native Rust Plugin feature is available here.

Impact Detail

If using an impacted configuration, the Router will load entire HTTP request bodies into memory without respect to other HTTP request size-limiting configurations like limits.httpmaxrequestbytes. This can cause the Router to be out-of-memory (OOM) terminated if a sufficiently large request is sent to the Router.

By default, the Router sets limits.httpmaxrequestbytes to 2 MB. More information about the Router’s request limiting features is available here.

Patches

Apollo Router 1.52.1

If you have an impacted configuration as defined above, please upgrade to at least Apollo Router 1.52.1.

Workarounds If you cannot upgrade, you can mitigate the denial-of-service opportunity impacting External Coprocessors by setting the coprocessor.router.request.body configuration option to false. Please note that changing this configuration option will change the information sent to any coprocessors you have configured and may impact functionality implemented by those coprocessors.

If you have developed a Native Rust Plugin and cannot upgrade, you can update your plugin to either not accumulate the request body or enforce a maximum body size limit.

You can also mitigate this issue by limiting HTTP body payload sizes prior to the Router (e.g., in a proxy or web application firewall appliance).

References Apollo Router 1.52.1 Release Notes External Coprocessing documentation HTTP Request Limiting documentation Native Rust Plugin documentation

Other sources

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service vulnerability if all of the following are true: 1. The Apollo Router has been configured to support External Coprocessing. 2. The Apollo Router has been configured to send request bodies to coprocessors. This is a non-default configuration and must be configured intentionally by administrators. Instances of the Apollo Router running versions >=1.7.0 and <1.52.1 are impacted by a denial-of-service vulnerability if all of the following are true: 1. Router has been configured to use a custom-developed Native Rust Plugin. 2. The plugin accesses Request.routerrequest in the RouterService layer. 3. You are accumulating the body from Request.routerrequest into memory. If using an impacted configuration, the Router will load entire HTTP request bodies into memory without respect to other HTTP request size-limiting configurations like limits.httpmaxrequestbytes. This can cause the Router to be out-of-memory (OOM) terminated if a sufficiently large request is sent to the Router. By default, the Router sets limits.httpmaxrequestbytes to 2 MB. If you have an impacted configuration as defined above, please upgrade to at least Apollo Router 1.52.1. If you cannot upgrade, you can mitigate the denial-of-service opportunity impacting External Coprocessors by setting the coprocessor.router.request.body configuration option to false. Please note that changing this configuration option will change the information sent to any coprocessors you have configured and may impact functionality implemented by those coprocessors. If you have developed a Native Rust Plugin and cannot upgrade, you can update your plugin to either not accumulate the request body or enforce a maximum body size limit. You can also mitigate this issue by limiting HTTP body payload sizes prior to the Router (e.g., in a proxy or web application firewall appliance).

NVD

Affected Software

4 affected componentsFixes available
rust/apollo-router>=1.7.0<1.52.1
1.52.1
apollographql Apollo-router Rust>=1.7.0<1.52.1
apollographql Apollo Helms-charts Router>=1.7.0<1.52.1
apollographql Apollo Router>=1.7.0<1.52.1

Event History

Aug 27, 2024
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:14 PM
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-43783?

CVE-2024-43783 is classified as a denial-of-service vulnerability, which can potentially impact the availability of the affected service.

2

How do I fix CVE-2024-43783?

To mitigate CVE-2024-43783, users should upgrade to a patched version of Apollo Router, specifically version 1.52.1 or later.

3

Which versions of Apollo Router are affected by CVE-2024-43783?

CVE-2024-43783 affects versions of Apollo Router between 1.7.0 and 1.52.1, inclusive.

4

What components are impacted by CVE-2024-43783?

CVE-2024-43783 impacts instances of Apollo Router that utilize external coprocessing or native Rust plugins accessing the Router request body.

5

Is CVE-2024-43783 a result of a configuration issue?

Yes, the denial-of-service vulnerability in CVE-2024-43783 may arise from specific configurations in external coprocessing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203