Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache APISIX — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in Apache APISIX, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities specifically affecting the open-source API gateway and microservice API management platform, Apache APISIX, focusing on weaknesses in its routing, authentication, and plugin systems. The collection compiles advisories released between 2022 and 2024, covering critical flaws such as remote code execution risks, denial of service conditions, and cross-site request forgery issues found in various versions. Readers can use this resource to track the vendor’s advisory history, analyze trends in a specific weakness class like input validation errors or deserialization bugs, and review the complete vulnerability lifecycle for the product. The data is structured to support both quick reference and deeper security analysis without including individual CVE identifiers in the summary view.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-94276 Apache APISIX: Openid-connect introspection validation issue CWE-287 5.1 Medium 2026-10-01
CVE-2026-94269 Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch CWE-647 6.3 Medium 2026-10-01
CVE-2026-94250 Apache APISIX: Batch response aggregation can exhaust worker memory CWE-770 8.2 High 2026-10-01
CVE-2026-94220 Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin CWE-352 2.1 Low 2026-10-01
CVE-2026-94212 Apache APISIX: unauthenticated impersonation issue in saml-auth CWE-347 6.4 Medium 2026-10-01
CVE-2026-82806 Apache APISIX: cross-request permission pollution via static permission list mutation CWE-488 5.3 Medium 2026-10-01
CVE-2026-78242 Apache APISIX: data-mask may fail to redact request headers in logger output CWE-532 5.7 Medium 2026-10-01
CVE-2026-74848 Apache APISIX: Cross-user response poisoning in serverless plugins CWE-444 7.0 High 2026-08-27
CVE-2026-75005 Apache APISIX: Unauthenticated CPU-exhaustion DoS CWE-407 8.7 High 2026-08-27
CVE-2026-75020 Apache APISIX: ldap-auth plugin cross-subtree identity impersonation CWE-90 7.0 High 2026-08-27
CVE-2026-63041 Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers CWE-807 5.3 Medium 2026-08-26
CVE-2026-49872 Apache APISIX: Improper authentication in cas-auth plugin CWE-287 - - 2026-06-19
CVE-2026-49871 Apache APISIX: cas-auth login CSRF / session injection issue CWE-352 - - 2026-06-19
CVE-2026-47341 Apache APISIX: Session replay issue in hmac-auth CWE-294 - - 2026-06-19
CVE-2026-48895 Apache APISIX: Cas-auth Host header influence on CAS service URL CWE-601 - - 2026-06-19
CVE-2026-49231 Apache APISIX: Identity spoofing issue in APISIX opa plugin CWE-290 - - 2026-06-19
CVE-2026-49230 Apache APISIX: Authentication bypass in jwe-decrypt CWE-354 - - 2026-06-19
CVE-2026-44915 Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value CWE-601 - - 2026-06-19
CVE-2026-44087 Apache APISIX: Openid-connect plugin Identity Header Spoofing CWE-345 - - 2026-06-19
CVE-2026-47339 Apache APISIX: authz-casdoor incorrect session sharing CWE-863 - - 2026-06-19
CVE-2026-44046 Apache APISIX: wolf-rbac plugin Identity Spoofing CWE-348 - - 2026-06-19
CVE-2026-39999 Apache APISIX: JWT Algorithm Confusion allows authentication bypass CWE-290 - - 2026-06-19
CVE-2026-39998 Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup CWE-20 - - 2026-06-19
CVE-2026-31923 Apache APISIX: Openid-connect `tls_verify` field is disabled by default CWE-319 7.5 - 2026-04-14
CVE-2026-31924 Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP CWE-319 7.5 - 2026-04-14
CVE-2026-31908 Apache APISIX: forward auth plugin allows header injection CWE-75 8.2 - 2026-04-14
CVE-2025-62232 Apache APISIX: basic-auth logs plaintext credentials at info level CWE-532 6.5 - 2025-10-31
CVE-2025-46647 Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect CWE-302 7.5AI High AI 2025-07-02
CVE-2024-32638 Apache APISIX: Forward-Auth Request Smuggling CWE-444 9.1 - 2024-05-02
CVE-2022-29266 apisix/jwt-auth may leak secrets in error response CWE-209 7.5 - 2022-04-20

All 34 known CVE vulnerabilities affecting Apache APISIX with full Chinese analysis, references, and POCs where available.