Apache APISIX 中 feishu-auth 和 dingtalk-auth 插件存在跨站请求伪造(CSRF)漏洞。 攻击者若能诱使用户点击一个精心构造的链接,可能导致该用户在受保护路由上的浏览器会话以攻击者的身份而非用户自身的身份建立。随后,用户在该会话中执行的所有操作(包括文件上传、表单提交以及账户绑定等)都将归属于攻击者的账户。 此漏洞影响 Apache APISIX 3.17.0 至 3.18.0 版本。 建议用户升级至 3.19.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 3.17.0 ~ 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream extern |
| CVE-2026-94250 | 8.2 HIGH | Apache APISIX: Batch response aggregation can exhaust worker memory |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX: unauthenticated impersonation issue in saml-auth |
| CVE-2026-94269 | 6.3 MEDIUM | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX: data-mask may fail to redact request headers in logger output |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-94276 | 5.1 MEDIUM | Apache APISIX: Openid-connect introspection validation issue |
No comments yet