CVE-2026-23897 | apollographql apollo-server up to 3.13.0/4.12.x/5.3.x startStandaloneServer redos (GHSA-mp6q-xf9x-fwf7)
A vulnerability marked as problematic has been reported in apollographql apollo-server up to 3.13.0/4.12.x/5.3.x. Affected by this issue is some unknown functionality. The manipulation of the argument startStandaloneServer leads to inefficient regular expression complexity.
This vulnerability is documented as CVE-2026-23897. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.