Apache / Apache Apisix
34 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-94276 | Apache APISIX: Openid-connect introspection validation issue | MEDIUM | 5.1 | Oct 1, 2026 |
| CVE-2026-94269 | Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch | MEDIUM | 6.3 | Oct 1, 2026 |
| CVE-2026-94250 | Apache APISIX: Batch response aggregation can exhaust worker memory | HIGH | 8.2 | Oct 1, 2026 |
| CVE-2026-94220 | Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin | LOW | 2.1 | Oct 1, 2026 |
| CVE-2026-94212 | Apache APISIX: unauthenticated impersonation issue in saml-auth | MEDIUM | 6.4 | Oct 1, 2026 |
| CVE-2026-82806 | Apache APISIX: cross-request permission pollution via static permission list mutation | MEDIUM | 5.3 | Oct 1, 2026 |
| CVE-2026-78242 | Apache APISIX: data-mask may fail to redact request headers in logger output | MEDIUM | 5.7 | Oct 1, 2026 |
| CVE-2026-74848 | Apache APISIX: Cross-user response poisoning in serverless plugins | HIGH | 7.0 | Aug 27, 2026 |
| CVE-2026-75005 | Apache APISIX: Unauthenticated CPU-exhaustion DoS | HIGH | 8.7 | Aug 27, 2026 |
| CVE-2026-75020 | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation | HIGH | 7.0 | Aug 27, 2026 |
| CVE-2026-63041 | Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers | MEDIUM | 5.3 | Aug 26, 2026 |
| CVE-2026-49872 | Apache APISIX: Improper authentication in cas-auth plugin | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-49871 | Apache APISIX: cas-auth login CSRF / session injection issue | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-47341 | Apache APISIX: Session replay issue in hmac-auth | MEDIUM | 6.3 | Jun 19, 2026 |
| CVE-2026-48895 | Apache APISIX: Cas-auth Host header influence on CAS service URL | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-49231 | Apache APISIX: Identity spoofing issue in APISIX opa plugin | LOW | 2.3 | Jun 19, 2026 |
| CVE-2026-49230 | Apache APISIX: Authentication bypass in jwe-decrypt | MEDIUM | 6.3 | Jun 19, 2026 |
| CVE-2026-44915 | Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-44087 | Apache APISIX: Openid-connect plugin Identity Header Spoofing | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-47339 | Apache APISIX: authz-casdoor incorrect session sharing | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-44046 | Apache APISIX: wolf-rbac plugin Identity Spoofing | LOW | 2.3 | Jun 19, 2026 |
| CVE-2026-39999 | Apache APISIX: JWT Algorithm Confusion allows authentication bypass | HIGH | 7.0 | Jun 19, 2026 |
| CVE-2026-39998 | Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup | MEDIUM | 5.8 | Jun 19, 2026 |
| CVE-2026-31923 | Apache APISIX: Openid-connect `tls_verify` field is disabled by default | HIGH | 7.5 | Apr 14, 2026 |
| CVE-2026-31924 | Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP | MEDIUM | 5.3 | Apr 14, 2026 |
Showing 1 to 25 of 34 CVEs