Apache APISIX 中存在一个“使用非规范化 URL 路径进行授权决策”的漏洞。 在某些配置下,如果一条宽松的路由与一条受保护的路由存在重叠,攻击者可以构造一个经过编码的路径,使其绕过匹配路由所定义的安全策略,从而访问到本不应被该路由策略覆盖的上游端点。原本应被拒绝的请求反而会被处理,导致未认证用户能够访问受保护的上游端点。 该漏洞影响 Apache APISIX 从 2.14.1 到 3.18.0 的版本。 建议用户升级到 3.19.0 版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 2.14.1≤ 3.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 2.14.1 ~ 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream extern |
| CVE-2026-94250 | 8.2 HIGH | Apache APISIX: Batch response aggregation can exhaust worker memory |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX: unauthenticated impersonation issue in saml-auth |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX: data-mask may fail to redact request headers in logger output |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-94276 | 5.1 MEDIUM | Apache APISIX: Openid-connect introspection validation issue |
| CVE-2026-94220 | 2.1 LOW | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin |
| CVE-2026-56154 | Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} | |
| CVE-2026-42528 | Apache HTTP Server: mod_dav shared lock overflow | |
| CVE-2026-42356 | Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI direct | |
| CVE-2026-46729 | Apache HTTP Server: mod_heartmonitor denial of service | |
| CVE-2026-47360 | Apache HTTP Server: mod_session: Session cookie not removed during internal redirect | |
| CVE-2026-48005 | Apache HTTP Server: mod_auth_digest reauthentication attack | |
| CVE-2026-56153 | Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char | |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | |
| CVE-2026-56449 | Apache HTTP Server: mod_proxy_html: crash in dump_content | |
| CVE-2026-57941 | Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-ent | |
| CVE-2026-58415 | Apache HTTP Server: mod_dav_fs property database read access | |
| CVE-2026-59685 | Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on C | |
| CVE-2026-59797 | Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet