CVE-2026-48895
published 2026-06-19CVE-2026-48895: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an…
PriorityP342high7.2CVSS 3.1
AVNACLPRNUINSCCLILAN
EPSS
0.41%
33.1th percentile
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apisix | >= 3.0.0 < 3.17.0 | 3.17.0 |
| apache_software_foundation | apache_apisix | 3.0.0 – 3.16.0 | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache APISIX up to 3.16.0 redirect (EUVD-2026-38023)
vuldb·2026-06-25·CVSS 7.2
CVE-2026-48895 [HIGH] Apache APISIX up to 3.16.0 redirect (EUVD-2026-38023)
A vulnerability described as problematic has been identified in Apache APISIX up to 3.16.0. The affected element is an unknown function. Such manipulation leads to open redirect.
This vulnerability is documented as CVE-2026-48895. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
ghsa_unreviewed·2026-06-19
CVE-2026-48895 [LOW] CWE-601 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-19
Published