Apache APISIX 中 batch-requests 插件存在“无限制或无节流地分配资源”的漏洞。 未经身份验证的攻击者可以通过使用 batch-requests 插件的路由,并公开暴露批量请求端点,导致网关工作进程因内存耗尽(OOM)而崩溃。该漏洞影响 Apache APISIX 1.3.0 至 3.18.0 版本。 建议用户升级至 3.19.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 1.3.0 ~ 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream extern |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX: unauthenticated impersonation issue in saml-auth |
| CVE-2026-94269 | 6.3 MEDIUM | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX: data-mask may fail to redact request headers in logger output |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-94276 | 5.1 MEDIUM | Apache APISIX: Openid-connect introspection validation issue |
| CVE-2026-94220 | 2.1 LOW | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin |
No comments yet