Apache APISIX 存在算法复杂度低效(Inefficient Algorithmic Complexity)漏洞。 在 路由中,一个微小的请求即可导致网关工作进程长时间占用 100% CPU。 此问题影响 Apache APISIX 版本:3.17.0。 建议用户升级至 3.18.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-74848 | 7.0 HIGH | Apache APISIX: Cross-user response poisoning in serverless plugins |
| CVE-2026-75020 | 7.0 HIGH | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation |
No comments yet