Apache APISIX 中存在一个“LDAP 查询中特殊元素未正确中和(即 LDAP 注入)”的漏洞。 持有 LDAP 目录中某个条目有效凭据的调用方,可以通过 APISIX 身份验证,并映射为另一个条目的消费者,而该条目本应被该插件配置的访问控制范围排除在外。 此问题影响 Apache APISIX 的 2.11.0 到 3.17.0 版本。 建议用户升级到 3.18.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 2.11.0 ~ 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75005 | 8.7 HIGH | Apache APISIX: Unauthenticated CPU-exhaustion DoS |
| CVE-2026-74848 | 7.0 HIGH | Apache APISIX: Cross-user response poisoning in serverless plugins |
No comments yet