Apache Software Foundation Apache Apisix vulnerabilities
23 known vulnerabilities affecting apache_software_foundation/apache_apisix.
Total CVEs
23
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH8MEDIUM8
Vulnerabilities
Page 2 of 2
CVE-2025-46647P4MEDIUMCVSS 5.3fixed in 3.12.02025-07-02
CVE-2025-46647 [MEDIUM] CWE-302 CVE-2025-46647: A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an imp
A vulnerability of plugin openid-connect in Apache APISIX.
This vulnerability will only have an impact if all of the following conditions are met:
1. Use the openid-connect plugin with introspection mode
2. The auth service connected to openid-connect provides services to multiple issuers
3. Multiple issuers share the same private key and relies onl
nvd
CVE-2026-44915P4MEDIUMCVSS 6.1≥ 3.0.0, ≤ 3.16.02026-06-19
CVE-2026-44915 [MEDIUM] CWE-601 CVE-2026-44915: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default con
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
nvd
CVE-2026-31924P4MEDIUMCVSS 5.3≥ 2.99.0, ≤ 3.15.02026-04-14
CVE-2026-31924 [MEDIUM] CWE-319 CVE-2026-31924: Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls l
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
tencent-cloud-cls log export uses plaintext HTTP
This issue affects Apache APISIX: from 2.99.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue.
nvd
← Previous2 / 2