VendorsApacheapisixall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
Published 2022-02-11 · Analyzed
9.8KEV1 PoCEPSS 0.961
CVE-2022-25757
Apache APISIX: the body_schema check in request-validation plugin can be bypassed
Published 2022-03-28 · Modified
9.8EPSS 0.025
CVE-2026-49871
Apache APISIX: cas-auth login CSRF / session injection issue
Published 2026-06-19 · Analyzed
9.3EPSS 0.004
CVE-2026-39999
Apache APISIX: JWT Algorithm Confusion allows authentication bypass
Published 2026-06-19 · Analyzed
9.1EPSS 0.006
CVE-2026-31908
Apache APISIX: forward auth plugin allows header injection
Published 2026-04-14 · Analyzed
9.1EPSS 0.005
CVE-2026-49230
Apache APISIX: Authentication bypass in jwe-decrypt
Published 2026-06-19 · Analyzed
9.1EPSS 0.003
CVE-2026-44087
Apache APISIX: Openid-connect plugin Identity Header Spoofing
Published 2026-06-19 · Analyzed
9.1EPSS 0.003
CVE-2026-63041
Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Published 2026-08-26 · Analyzed
8.8EPSS 0.007
CVE-2026-39998
Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
Published 2026-06-19 · Analyzed
8.8EPSS 0.007
CVE-2026-75005
Apache APISIX: Unauthenticated CPU-exhaustion DoS
Published 2026-08-27 · Analyzed
8.7EPSS 0.008
CVE-2026-75020
Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Published 2026-08-27 · Analyzed
8.1EPSS 0.005
CVE-2026-49872
Apache APISIX: Improper authentication in cas-auth plugin
Published 2026-06-19 · Analyzed
8.1EPSS 0.005
CVE-2026-47339
Apache APISIX: authz-casdoor incorrect session sharing
Published 2026-06-19 · Analyzed
8.1EPSS 0.005
CVE-2025-27446
Apache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges
Published 2025-07-06 · Modified
7.8EPSS 0.002
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2021-43557
Path traversal in request_uri variable
Published 2021-11-22 · Modified
7.5EPSS 0.129
CVE-2022-29266
apisix/jwt-auth may leak secrets in error response
Published 2022-04-20 · Modified
7.5EPSS 0.081
CVE-2026-74848
Apache APISIX: Cross-user response poisoning in serverless plugins
Published 2026-08-27 · Analyzed
7.5EPSS 0.006
CVE-2025-62232
Apache APISIX: basic-auth logs plaintext credentials at info level
Published 2025-10-31 · Analyzed
7.5EPSS 0.004
CVE-2026-31923
Apache APISIX: Openid-connect `tls_verify` field is disabled by default
Published 2026-04-14 · Analyzed
7.5EPSS 0.003
CVE-2026-48895
Apache APISIX: Cas-auth Host header influence on CAS service URL
Published 2026-06-19 · Analyzed
7.2EPSS 0.006
CVE-2020-13945
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.
Published 2020-12-07 · Modified
6.5EPSS 0.730
CVE-2026-47341
Apache APISIX: Session replay issue in hmac-auth
Published 2026-06-19 · Analyzed
6.5EPSS 0.007
CVE-2024-32638
Apache APISIX: Forward-Auth Request Smuggling
Published 2024-05-02 · Analyzed
6.3EPSS 0.011
CVE-2026-44915
Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
Published 2026-06-19 · Analyzed
6.1EPSS 0.006
CVE-2026-44046
Apache APISIX: wolf-rbac plugin Identity Spoofing
Published 2026-06-19 · Analyzed
5.8EPSS 0.005
CVE-2026-49231
Apache APISIX: Identity spoofing issue in APISIX opa plugin
Published 2026-06-19 · Analyzed
5.4EPSS 0.006
CVE-2025-46647
Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect
Published 2025-07-02 · Modified
5.3EPSS 0.005
CVE-2026-31924
Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP
Published 2026-04-14 · Analyzed
5.3EPSS 0.002