cbcvebase.

Apache Software Foundation Apache Apisix vulnerabilities

23 known vulnerabilities affecting apache_software_foundation/apache_apisix.

Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH8MEDIUM8

Vulnerabilities

Page 1 of 2
CVE-2022-24112P1CRITICALCVSS 9.8KEVPoC≥ Apache APISIX 2.12, < 2.12.1≥ Apache APISIX 2.10, < 2.10.4+1 more2022-02-11
CVE-2022-24112 [CRITICAL] CWE-290 CVE-2022-24112: An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Adm An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But the
nvd
CVE-2020-13945P2MEDIUMCVSS 6.5PoCv1.2v1.3+2 more2020-12-07
CVE-2020-13945 [MEDIUM] CVE-2020-13945: In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rul In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.
nvd
CVE-2026-39999P2CRITICALCVSS 9.1≥ 2.2, ≤ 3.16.02026-06-19
CVE-2026-39999 [CRITICAL] CWE-290 CVE-2026-39999: Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypas Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.
nvd
CVE-2026-31908P2CRITICALCVSS 9.1≥ 2.12.0, ≤ 3.15.02026-04-14
CVE-2026-31908 [CRITICAL] CWE-75 CVE-2026-31908: Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configu Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.
nvd
CVE-2026-49230P2CRITICALCVSS 9.1≥ 3.8.0, ≤ 3.16.02026-06-19
CVE-2026-49230 [CRITICAL] CWE-354 CVE-2026-49230: Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2022-25757P3CRITICALCVSS 9.8≥ Apache APISIX, ≤ 2.12.12022-03-28
CVE-2022-25757 [CRITICAL] CWE-20 CVE-2022-25757: In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the la In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example, `{"string_payload":"bad","string_payload":"good"}` can be used to hide the "bad
nvd
CVE-2026-44087P3CRITICALCVSS 9.1≥ 2.3, ≤ 3.16.02026-06-19
CVE-2026-44087 [CRITICAL] CWE-345 CVE-2026-44087: Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect p Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources. This issue affects Apache APISIX: from 2.3 through 3.16.0. Users are
nvd
CVE-2026-39998P3HIGHCVSS 8.8≥ 2.12.0, ≤ 3.16.02026-06-19
CVE-2026-39998 [HIGH] CWE-20 CVE-2026-39998: Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certai Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2021-43557P3HIGHCVSS 7.5≥ 1.5, < Apache APISIX 1.5*2021-11-22
CVE-2021-43557 [HIGH] CWE-77 CVE-2021-43557: The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $req The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypas
nvd
CVE-2026-49872P3HIGHCVSS 8.1≥ 3.0.0, ≤ 3.16.02026-06-19
CVE-2026-49872 [HIGH] CWE-287 CVE-2026-49872: Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2026-47339P3HIGHCVSS 8.1≥ 2.14.1, ≤ 3.16.02026-06-19
CVE-2026-47339 [HIGH] CWE-863 CVE-2026-47339: Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue affects Apache APISIX: from 2.14.1 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2026-49871P3CRITICALCVSS 9.3≥ 3.0.0, ≤ 3.16.02026-06-19
CVE-2026-49871 [CRITICAL] CWE-352 CVE-2026-49871: Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the victim's browser to become authenticated as a different identity. Actions the victim takes upstream are then attributed to attackers
nvd
CVE-2022-29266P3HIGHCVSS 7.5≥ Apache APISIX, ≤ 2.13.02022-04-20
CVE-2022-29266 [HIGH] CWE-209 CVE-2022-29266: In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secre In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.
nvd
CVE-2025-62232P3HIGHCVSS 7.5≥ 1.0, < 3.142025-10-31
CVE-2025-62232 [HIGH] CWE-532 CVE-2025-62232: Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following commit: https://github.com/apache/apisix/pull/12629 Users are recommended to
nvd
CVE-2026-31923P3HIGHCVSS 7.5≥ 0.7, ≤ 3.15.02026-04-14
CVE-2026-31923 [HIGH] CWE-319 CVE-2026-31923: Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.
nvd
CVE-2026-48895P3HIGHCVSS 7.2≥ 3.0.0, ≤ 3.16.02026-06-19
CVE-2026-48895 [HIGH] CWE-601 CVE-2026-48895: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker co URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2026-47341P3MEDIUMCVSS 6.5≥ 3.11.0, ≤ 3.16.02026-06-19
CVE-2026-47341 [MEDIUM] CWE-294 CVE-2026-47341: Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from c Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2024-32638P3MEDIUMCVSS 6.3≥ 3.8.0, ≤ 3.9.02024-05-02
CVE-2024-32638 [MEDIUM] CWE-444 CVE-2024-32638: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APIS Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
nvd
CVE-2026-49231P3MEDIUMCVSS 5.4≥ 3.5.0, ≤ 3.16.02026-06-19
CVE-2026-49231 [MEDIUM] CWE-290 CVE-2026-49231: Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed iden Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue affects Apache APISIX: from 3.5.0 through 3.16.0. Users are recommended to
nvd
CVE-2026-44046P4MEDIUMCVSS 5.8≥ 1.2.0, ≤ 3.16.02026-06-19
CVE-2026-44046 [MEDIUM] CWE-348 CVE-2026-44046: Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from 1.2.0 through 3.16.0. Users are recommended to upgrade to version 3.17.
nvd
Apache Software Foundation Apache Apisix vulnerabilities | cvebase