CVE-2026-94276
- EPSS 0.49%
- Veröffentlicht 01.10.2026 11:02:36
- Zuletzt bearbeitet 01.10.2026 15:17:36
Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted...
CVE-2026-94269
- EPSS 0.42%
- Veröffentlicht 01.10.2026 11:02:20
- Zuletzt bearbeitet 01.10.2026 15:17:36
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's pol...
CVE-2026-94250
- EPSS 0.32%
- Veröffentlicht 01.10.2026 11:01:41
- Zuletzt bearbeitet 01.10.2026 15:17:36
Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint ...
CVE-2026-94220
- EPSS 0.22%
- Veröffentlicht 01.10.2026 11:01:26
- Zuletzt bearbeitet 01.10.2026 15:17:36
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under th...
CVE-2026-94212
- EPSS 0.27%
- Veröffentlicht 01.10.2026 11:01:11
- Zuletzt bearbeitet 01.10.2026 15:17:35
Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX...
CVE-2026-82806
- EPSS 0.4%
- Veröffentlicht 01.10.2026 10:58:32
- Zuletzt bearbeitet 01.10.2026 15:17:32
Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later reques...
CVE-2026-78242
- EPSS 0.15%
- Veröffentlicht 01.10.2026 10:58:13
- Zuletzt bearbeitet 01.10.2026 15:17:31
Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure. This issue affects Apache APISIX: 3.17.0....
CVE-2026-74848
- EPSS 0.49%
- Veröffentlicht 27.08.2026 09:16:06
- Zuletzt bearbeitet 31.08.2026 19:00:05
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affec...
CVE-2026-75005
- EPSS 0.49%
- Veröffentlicht 27.08.2026 09:15:32
- Zuletzt bearbeitet 28.08.2026 20:40:37
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommen...
CVE-2026-75020
- EPSS 0.5%
- Veröffentlicht 27.08.2026 09:14:33
- Zuletzt bearbeitet 31.08.2026 19:00:26
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through APISIX as a consumer mapped to a d...