CVE-2026-32621 is a prototype pollution vulnerability in Apollo Federation affecting gateway query plan execution prior to versions 2.9.6, 2.10.5, 2.11.6, 2.12.3, and 2.13.2. The issue stems from incomplete sanitization of attacker-controlled property names during processing in the gateway, allowing writes to prototype-inheritable properties on JavaScript objects. A malicious client can trigger the flaw directly by crafting GraphQL operations that use field aliases and/or variable names such as proto, constructor, or prototype. In an alternate attack path, a compromised or malicious federated subgraph can return crafted JSON response payloads containing prototype-targeting keys, which are then processed by the gateway and used to pollute Object.prototype in the Node.js process. Because the pollution occurs in the gateway runtime, the effect can persist across subsequent request handling within that process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone JavaScript PoC for CVE-2026-32621, a prototype-pollution flaw in Apollo Federation/@apollo/gateway deepMerge logic. It is not tied to a major exploit framework. The main exploit file is `exploit.js`, which provides both a local demonstration of the vulnerable merge behavior and a remote mode that sends crafted GraphQL POST requests to a target endpoint. The exploit’s core capability is to induce `Object.prototype` pollution using attacker-controlled keys such as `__proto__`, `constructor`, and `prototype`, primarily through GraphQL field aliases and maliciously structured JSON/subgraph responses. Documented impacts include privilege-escalation-like property injection (`isAdmin`), cross-request persistence, process-wide behavior corruption, and DoS by breaking methods like `toString`. Repository structure: `exploit.js` is the primary PoC/CLI entry point; `setup_vulnerable.js` is a minimal vulnerable gateway simulator exposing `/graphql`; `test_exploit.js` contains unit tests validating vulnerable vs patched deepMerge behavior; `e2e_test.js` launches the simulator, sends exploit payloads, and verifies persistence across requests; `README.md`, `USAGE.md`, and `DIAGRAM.md` provide vulnerability explanation, usage instructions, and attack-flow diagrams; `package.json` defines simple Node entry scripts with no dependencies. Notable exploit behaviors visible in code and docs: alias-based payload `query { __proto__: products { id } }`, constructor/prototype chain payload `query { constructor: products { prototype: id } }`, nested alias chains, variable-name abuse attempts, and malicious subgraph JSON such as `{"data":{"__proto__":{"polluted":true,"isAdmin":true}}}`. The simulator’s vulnerable path is explicit: it accepts POST requests on `/graphql`, parses JSON, fabricates subgraph responses containing dangerous keys when the query includes `__proto__` or `constructor`, and merges them with an unsafe deepMerge implementation. Successful exploitation is reflected in response `extensions.polluted` and inherited properties on newly created objects. Overall, this is a real operational PoC exploit repository with local and network-delivered exploitation paths, plus validation tooling.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.