Apache APISIX
11 known vulnerabilities in Apache APISIX, 1 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2022-24112 CVSS 9.8 critical · actively exploited Apache APISIX Authentication Bypass Vulnerability
Latest vulnerabilities
- CVE-2026-94276 CVSS 5.1 medium Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an…
- CVE-2026-94269 CVSS 6.3 medium Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route…
- CVE-2026-94250 CVSS 8.2 high Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller…
- CVE-2026-94220 CVSS 2.1 low Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user…
- CVE-2026-94212 CVSS 6.4 medium Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user…
- CVE-2026-82806 CVSS 5.3 medium Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under…
- CVE-2026-78242 CVSS 5.7 medium Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to…
- CVE-2026-75020 CVSS 7.0 high Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds…
- CVE-2026-75005 CVSS 8.7 high Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an…
- CVE-2026-74848 CVSS 7.0 high Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make…
- CVE-2022-24112 CVSS 9.8 critical · actively exploited Apache APISIX Authentication Bypass Vulnerability