# Apollo's Response to CVE-2023-38545

DevFeed: [Apollo's Response to CVE-2023-38545](<https://devfeed.tech/articles/apollo-s-response-to-cve-2023-38545-23227.md>)

Original publisher: [Read original article](<https://www.apollographql.com/blog/apollos-response-to-cve-2023-38545>)

Author: Matt Peake

Published: 2023-10-09T14:59:26Z

Content type: release

Language: en

Sources: [Apollo Blog](<https://devfeed.tech/sources/apollo-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [apollo-client](<https://devfeed.tech/topics/apollo-client.md>), [apollo-server](<https://devfeed.tech/topics/apollo-server.md>), [GraphOS](<https://devfeed.tech/topics/graphos.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Kotlin](<https://devfeed.tech/topics/kotlin.md>)

Tags: [apollo](<https://devfeed.tech/tags/apollo.md>), [apollo-client](<https://devfeed.tech/tags/apollo-client.md>), [cve](<https://devfeed.tech/tags/cve.md>), [graphos](<https://devfeed.tech/tags/graphos.md>), [graphql](<https://devfeed.tech/tags/graphql.md>), [ios](<https://devfeed.tech/tags/ios.md>), [kotlin](<https://devfeed.tech/tags/kotlin.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [security](<https://devfeed.tech/tags/security.md>), [socks5](<https://devfeed.tech/tags/socks5.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

## AI overview

Apollo reports that Apollo Router, Apollo Client, Apollo Server, Apollo Kotlin, Apollo iOS, and Rover are not affected by CVE-2023-38545. GraphOS includes containers with affected curl versions, but Apollo says it does not use SOCKS5 proxies in the GraphOS environment, a key requirement for exploiting the vulnerability.

## Source excerpt

October 12, 2023 Update Yesterday, the curl project released details regarding CVE-2023-38545. We want to provide an update on Apollo's impact from this vulnerability. As mentioned in our original post, Apollo Router, Apollo Client, Apollo Server, Apollo Kotlin, Apollo iOS, and Rover do not rely on curl and are not affected by this vulnerability. The build processes for these projects do utilize curl, but exclusively communicate with trusted domains and are therefore not impacted.