cbcvebase.

Apache Apisix vulnerabilities

25 known vulnerabilities affecting apache/apisix.

Total CVEs
25
CISA KEV
2
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH10MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2026-49231P3MEDIUMCVSS 5.4≥ 3.5.0, < 3.17.02026-06-19
CVE-2026-49231 [MEDIUM] CWE-290 CVE-2026-49231: Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed iden Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are recommended to
nvd
CVE-2026-44046P4MEDIUMCVSS 5.8≥ 1.2, < 3.17.02026-06-19
CVE-2026-44046 [MEDIUM] CWE-348 CVE-2026-44046: Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from 1.2.0 through 3.16.0. Users are recommended to upgrade to version 3.17.
nvd
CVE-2025-46647P4MEDIUMCVSS 5.3fixed in 3.12.02025-07-02
CVE-2025-46647 [MEDIUM] CWE-302 CVE-2025-46647: A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an imp A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies onl
nvd
CVE-2026-44915P4MEDIUMCVSS 6.1≥ 3.0.0, < 3.17.02026-06-19
CVE-2026-44915 [MEDIUM] CWE-601 CVE-2026-44915: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default con URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2026-31924P4MEDIUMCVSS 5.3≥ 2.99.0, < 3.16.02026-04-14
CVE-2026-31924 [MEDIUM] CWE-319 CVE-2026-31924: Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls l Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.
nvd
Apache Apisix vulnerabilities | cvebase