Apolloconfig Apollo
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Apolloconfig Apollo.
By the Year
In 2026 there have been 3 vulnerabilities in Apolloconfig Apollo with an average score of 7.2 out of ten. Apollo did not have any published security vulnerabilities last year. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3 | 7.17 |
| 2025 | 0 | 0.00 |
| 2024 | 3 | 5.37 |
| 2023 | 2 | 6.60 |
It may take a day or so for new Apollo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apolloconfig Apollo Security Vulnerabilities
Apollo <2.5.0: Auth Bypass in Release Permission Checks (CVE-2025-32781)
CVE-2025-32781
6.5 - Medium
- July 15, 2026
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.0, Apollo Portal does not verify application and namespace permissions when an authenticated user requests a release by ID through GET /envs/{env}/releases/{releaseId} while configView.memberOnly.envs is enabled, allowing a low-privileged Portal user who obtains or guesses a valid releaseId to read configuration data from other applications and namespaces without calling UserPermissionValidator.shouldHideConfigToCurrentUser(...). This issue is fixed in version 2.5.0.
Insecure Direct Object Reference / IDOR
Apollo ConfigService 2.5.2 Unauthenticated Access via AppID Variants
CVE-2026-59954
7.5 - High
- July 15, 2026
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to configuration data when AccessKey or management key authentication is enabled because ConfigService can accept a non-canonical appId variant during authentication while downstream request handling resolves it to the protected app, including accent variants under accent-insensitive collations or trailing-space variants under PAD SPACE collations on /configs and /configfiles endpoints. This issue is fixed in version 2.5.2.
Improper Input Validation
Apollo ConfigService Unauth Access via Raw Configs (pre-2.5.2)
CVE-2026-59955
7.5 - High
- July 15, 2026
Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior to 2.5.2, Apollo ConfigService may allow unauthorized access to raw configuration data when AccessKey or management key authentication is enabled because requests under /configfiles/raw/{appId}/{clusterName}/{namespace} are parsed for authentication as appId raw instead of the actual path appId, causing ConfigService to look up AccessKey secrets for raw before verifying the request signature and potentially continue without signature verification for the target appId. This issue is fixed in version 2.5.2.
Improper Input Validation
Apollo ConfigMgr 2.3.0 Fixed Sync Config Permission Bypass
CVE-2024-43397
4.3 - Medium
- August 20, 2024
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with an input parameter check which was released in version 2.3.0.
Apollo v2.2.0 Remote Info Disclosure via Crafted Request
CVE-2024-42662
7.5 - High
- August 20, 2024
An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.
Apollo 2.0.0/1 Improper Auth via /users Config Center
CVE-2022-4962
4.3 - Medium
- January 12, 2024
A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the component Configuration Center. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. VDB-250430 is the identifier assigned to this vulnerability. NOTE: The maintainer explains that user data information like user id, name, and email are not sensitive.
AuthZ
Apollo < 2.1.0 Exposes ConfigService/Eureka w/o Auth (CVE-2023-25570)
CVE-2023-25570
7.5 - High
- February 20, 2023
Apollo is a configuration management system. Prior to version 2.1.0, there are potential security issues if users expose apollo-configservice to the internet, which is not recommended. This is because there is no authentication feature enabled for the built-in eureka service. Malicious hackers may access eureka directly to mock apollo-configservice and apollo-adminservice. Login authentication for eureka was added in version 2.1.0. As a workaround, avoid exposing apollo-configservice to the internet.
Missing Authentication for Critical Function
Apollo Config Mgmt v<2.1.0: Low-Priv Priv Escal via Special Page
CVE-2023-25569
5.7 - Medium
- February 20, 2023
Apollo is a configuration management system. Prior to version 2.1.0, a low-privileged user can create a special web page. If an authenticated portal admin visits this page, the page can silently send a request to assign new roles for that user without any confirmation from the Portal admin. Cookie SameSite strategy was set to Lax in version 2.1.0. As a workaround, avoid visiting unknown source pages.
Session Riding
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apolloconfig Apollo or by Apolloconfig? Click the Watch button to subscribe.