Back

HIGH

Apache APISIX: JWT Algorithm Confusion allows authentication bypass

Published Jun 19, 2026

Description

Authentication Bypass by Spoofing vulnerability in Apache APISIX.

The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0.

Users are recommended to upgrade to version v3.17.0, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jun 19, 2026
Updated Jun 22, 2026
Reserved Apr 8, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Analyzed
Modified Jun 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Jun 19, 2026
Updated Jun 22, 2026
Exploited since n/a
EUVD-2026-38013