CVE-2026-31923
- EPSS 0.05%
- Veröffentlicht 14.04.2026 08:38:59
- Zuletzt bearbeitet 17.04.2026 18:39:45
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. User...
CVE-2026-31924
- EPSS 0.06%
- Veröffentlicht 14.04.2026 08:08:05
- Zuletzt bearbeitet 17.04.2026 18:38:47
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which...
CVE-2026-31908
- EPSS 0.15%
- Veröffentlicht 14.04.2026 08:06:18
- Zuletzt bearbeitet 17.04.2026 18:40:12
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upg...
CVE-2025-62232
- EPSS 0.09%
- Veröffentlicht 31.10.2025 08:48:23
- Zuletzt bearbeitet 05.11.2025 14:44:13
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has b...
CVE-2025-27446
- EPSS 0.04%
- Veröffentlicht 06.07.2025 06:15:21
- Zuletzt bearbeitet 04.11.2025 22:16:08
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-pl...
CVE-2025-46647
- EPSS 0.29%
- Veröffentlicht 02.07.2025 11:08:47
- Zuletzt bearbeitet 04.11.2025 22:16:15
A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-conne...
CVE-2024-32638
- EPSS 0.36%
- Veröffentlicht 02.05.2024 10:15:08
- Zuletzt bearbeitet 10.07.2025 16:00:20
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or ...
CVE-2023-44487
- EPSS 94.4%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 12.05.2026 15:10:32
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-29266
- EPSS 35.84%
- Veröffentlicht 20.04.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:50
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.
CVE-2022-25757
- EPSS 0.42%
- Veröffentlicht 28.03.2022 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:52:56
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation ...