Apache / Apisix
29 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-74848 | Apache APISIX: Cross-user response poisoning in serverless plugins | HIGH | 7.0 | Aug 27, 2026 |
| CVE-2026-75005 | Apache APISIX: Unauthenticated CPU-exhaustion DoS | HIGH | 8.7 | Aug 27, 2026 |
| CVE-2026-75020 | Apache APISIX: ldap-auth plugin cross-subtree identity impersonation | HIGH | 7.0 | Aug 27, 2026 |
| CVE-2026-63041 | Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers | MEDIUM | 5.3 | Aug 26, 2026 |
| CVE-2026-49872 | Apache APISIX: Improper authentication in cas-auth plugin | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-49871 | Apache APISIX: cas-auth login CSRF / session injection issue | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-47341 | Apache APISIX: Session replay issue in hmac-auth | MEDIUM | 6.3 | Jun 19, 2026 |
| CVE-2026-48895 | Apache APISIX: Cas-auth Host header influence on CAS service URL | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-49231 | Apache APISIX: Identity spoofing issue in APISIX opa plugin | LOW | 2.3 | Jun 19, 2026 |
| CVE-2026-49230 | Apache APISIX: Authentication bypass in jwe-decrypt | MEDIUM | 6.3 | Jun 19, 2026 |
| CVE-2026-44915 | Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value | LOW | 2.1 | Jun 19, 2026 |
| CVE-2026-44087 | Apache APISIX: Openid-connect plugin Identity Header Spoofing | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-47339 | Apache APISIX: authz-casdoor incorrect session sharing | MEDIUM | 5.3 | Jun 19, 2026 |
| CVE-2026-44046 | Apache APISIX: wolf-rbac plugin Identity Spoofing | LOW | 2.3 | Jun 19, 2026 |
| CVE-2026-39999 | Apache APISIX: JWT Algorithm Confusion allows authentication bypass | HIGH | 7.0 | Jun 19, 2026 |
| CVE-2026-39998 | Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup | MEDIUM | 5.8 | Jun 19, 2026 |
| CVE-2026-31923 | Apache APISIX: Openid-connect `tls_verify` field is disabled by default | HIGH | 7.5 | Apr 14, 2026 |
| CVE-2026-31924 | Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP | MEDIUM | 5.3 | Apr 14, 2026 |
| CVE-2026-31908 | Apache APISIX: forward auth plugin allows header injection | CRITICAL | 9.1 | Apr 14, 2026 |
| CVE-2025-62232 | Apache APISIX: basic-auth logs plaintext credentials at info level | HIGH | 7.5 | Oct 31, 2025 |
| CVE-2025-27446 | Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges | HIGH | 7.8 | Jul 6, 2025 |
| CVE-2025-46647 | Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect | MEDIUM | 5.3 | Jul 2, 2025 |
| CVE-2024-32638 | Apache APISIX: Forward-Auth Request Smuggling | MEDIUM | 6.3 | May 2, 2024 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2022-29266 | apisix/jwt-auth may leak secrets in error response | HIGH | 7.5 | Apr 20, 2022 |
Showing 1 to 25 of 29 CVEs