High severity7.5OSV Advisory· Published Apr 3, 2025· Updated Apr 15, 2026
CVE-2025-31485
CVE-2025-31485
Description
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL grant on a property might be cached with different objects. The ApiPlatform\GraphQl\Serializer\ItemNormalizer::isCacheKeySafe() method is meant to prevent the caching but the parent::normalize method that is called afterwards still creates the cache key and causes the issue. This vulnerability is fixed in 4.0.22 and 3.4.17.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
api-platform/graphqlPackagist | >= 4.0.0-alpha.1, < 4.0.22 | 4.0.22 |
api-platform/corePackagist | >= 4.0.0-alpha.1, < 4.0.22 | 4.0.22 |
api-platform/graphqlPackagist | < 3.4.17 | 3.4.17 |
api-platform/corePackagist | < 3.4.17 | 3.4.17 |
api-platform/corePackagist | >= 4.1.0-alpha.1, < 4.1.5 | 4.1.5 |
api-platform/graphqlPackagist | >= 4.1.0-alpha.1, < 4.1.5 | 4.1.5 |
Affected products
3- Range: push, remove, v1.0.0-beta, …
- ghsa-coords2 versions
>= 4.0.0-alpha.1, < 4.0.22+ 1 more
- (no CPE)range: >= 4.0.0-alpha.1, < 4.0.22
- (no CPE)range: >= 4.0.0-alpha.1, < 4.0.22
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-428q-q3vv-3fq3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-31485ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/api-platform/core/CVE-2025-31485.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/api-platform/graphql/CVE-2025-31485.yamlghsaWEB
- github.com/api-platform/core/commit/7af65aad13037d7649348ee3dcd88e084ef771f8nvdWEB
- github.com/api-platform/core/commit/cba3acfbd517763cf320167250c5bed6d569696anvdWEB
- github.com/api-platform/core/releases/tag/v3.4.17nvdWEB
- github.com/api-platform/core/security/advisories/GHSA-428q-q3vv-3fq3nvdWEB
News mentions
0No linked articles in our index yet.