Apache
Apache Apisix: vulnerabilidades y CVE
Apache Apisix tiene 36 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses27
Críticas3
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2022-24112 | Crítica (9.8) | 96% | ⚠ Explotación activa | 11 feb 2022 | An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94276 | Media (5.1) | — | — | 1 oct 2026 | Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active… |
| CVE-2026-94269 | Media (6.3) | — | — | 1 oct 2026 | Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint… |
| CVE-2026-94250 | Alta (8.2) | — | — | 1 oct 2026 | Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is… |
| CVE-2026-94220 | Baja (2.1) | — | — | 1 oct 2026 | Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected… |
| CVE-2026-94212 | Media (6.4) | — | — | 1 oct 2026 | Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This… |
| CVE-2026-82806 | Media (5.3) | — | — | 1 oct 2026 | Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could… |
| CVE-2026-78242 | Media (5.7) | — | — | 1 oct 2026 | Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure. This issue… |
| CVE-2026-75020 | Alta (7) | 0.55% | — | 27 ago 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry in the LDAP directory can authenticate through… |
| CVE-2026-75005 | Alta (8.7) | 0.74% | — | 27 ago 2026 | Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX:… |
| CVE-2026-74848 | Alta (7) | 0.59% | — | 27 ago 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on… |
| CVE-2026-63041 | Media (5.3) | 0.68% | — | 26 ago 2026 | Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the… |
| CVE-2026-49872 | Media (5.3) | 0.53% | — | 19 jun 2026 | Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source. This issue affects Apache… |
| CVE-2026-49871 | Baja (2.1) | 0.35% | — | 19 jun 2026 | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpage controlled by them can cause the… |
| CVE-2026-49231 | Baja (2.3) | 0.57% | — | 19 jun 2026 | Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to… |
| CVE-2026-49230 | Media (6.3) | 0.30% | — | 19 jun 2026 | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass. This issue affects Apache APISIX: from 3.8.0… |
| CVE-2026-48895 | Baja (2.1) | 0.65% | — | 19 jun 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue… |
| CVE-2026-47341 | Media (6.3) | 0.69% | — | 19 jun 2026 | Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from… |
| CVE-2026-47339 | Media (5.3) | 0.47% | — | 19 jun 2026 | Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials from a different source. This issue… |
| CVE-2026-44915 | Baja (2.1) | 0.64% | — | 19 jun 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache… |
| CVE-2026-44087 | Media (5.3) | 0.28% | — | 19 jun 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the… |
| CVE-2026-44046 | Baja (2.3) | 0.47% | — | 19 jun 2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based… |
| CVE-2026-39999 | Alta (7) | 0.64% | — | 19 jun 2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2… |
| CVE-2026-39998 | Media (5.8) | 0.68% | — | 19 jun 2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through… |
| CVE-2026-31924 | Media (5.3) | 0.36% | — | 14 abr 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to… |
| CVE-2026-31923 | Alta (7.5) | 0.37% | — | 14 abr 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX:… |
| CVE-2026-31908 | Crítica (9.1) | 0.60% | — | 14 abr 2026 | Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.… |
| CVE-2025-62232 | Alta (7.5) | 0.44% | — | 31 oct 2025 | Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential… |
| CVE-2025-27446 | Alta (7.8) | 0.19% | — | 6 jul 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue… |
| CVE-2025-46647 | Media (5.3) | 0.46% | — | 2 jul 2025 | A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth… |
| CVE-2024-32638 | Media (6.3) | 1.1% | — | 2 may 2024 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.