Apache APISIX 中存在 HTTP 请求解释不一致(“HTTP 请求/响应走私”)漏洞。 攻击者可以使其他客户端接收到由攻击者选择的响应或其他用户的响应,这发生在 serverless-plugin 路由上。 该问题影响 Apache APISIX 2.12.0 至 3.17.0 版本。 建议用户升级至 3.18.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 2.12.0 ~ 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75005 | 8.7 HIGH | Apache APISIX: Unauthenticated CPU-exhaustion DoS |
| CVE-2026-75020 | 7.0 HIGH | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation |
No comments yet