Apache APISIX 中存在一个身份验证不当(Improper Authentication)漏洞。 当某个路由配置了使用远程内省(remote introspection)的 openid-connect 插件,且授权服务器支持多个颁发者(issuer)时,一个针对某个颁发者内省结果为“有效”的令牌,可能会被错误地接受在仅限制为另一个颁发者的路由上。 该漏洞影响 Apache APISIX 3.12.0 至 3.18.0 版本。 建议用户升级至 3.19.0 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache APISIX | 3.12.0 ~ 3.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88789 | 8.6 HIGH | Apache Camel Quarkus: Camel Quarkus: Forced Xalan TransformerFactory drops upstream extern |
| CVE-2026-94250 | 8.2 HIGH | Apache APISIX: Batch response aggregation can exhaust worker memory |
| CVE-2026-94212 | 6.4 MEDIUM | Apache APISIX: unauthenticated impersonation issue in saml-auth |
| CVE-2026-94269 | 6.3 MEDIUM | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch |
| CVE-2026-78242 | 5.7 MEDIUM | Apache APISIX: data-mask may fail to redact request headers in logger output |
| CVE-2026-82806 | 5.3 MEDIUM | Apache APISIX: cross-request permission pollution via static permission list mutation |
| CVE-2026-94220 | 2.1 LOW | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin |
| CVE-2026-56154 | Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} | |
| CVE-2026-42528 | Apache HTTP Server: mod_dav shared lock overflow | |
| CVE-2026-42356 | Apache HTTP Server: limited RCE for some internal redirects to non-CGI files in CGI direct | |
| CVE-2026-46729 | Apache HTTP Server: mod_heartmonitor denial of service | |
| CVE-2026-47360 | Apache HTTP Server: mod_session: Session cookie not removed during internal redirect | |
| CVE-2026-48005 | Apache HTTP Server: mod_auth_digest reauthentication attack | |
| CVE-2026-56153 | Apache HTTP Server: mod_charset_lite: Heap overflow in finish_partial_char | |
| CVE-2026-63686 | Apache HTTP Server: mod_xml2enc crash on charset conversion failure | |
| CVE-2026-56449 | Apache HTTP Server: mod_proxy_html: crash in dump_content | |
| CVE-2026-57941 | Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-ent | |
| CVE-2026-58415 | Apache HTTP Server: mod_dav_fs property database read access | |
| CVE-2026-59685 | Apache HTTP Server: Out-of-Bounds Write in ap_directory_walk() Canonical-Name Rewrite on C | |
| CVE-2026-59797 | Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet