Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache APISIX — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in Apache APISIX, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation report for Apache APISIX, an open-source API gateway. The collected data covers diverse security weaknesses, ranging from critical remote code execution flaws to lower-severity configuration errors and information disclosures. This repository aggregates entries spanning from the product’s early development stages through the most recent quarterly releases, ensuring a historical perspective on the software’s security posture. By accessing this consolidated view, users can efficiently track advisory updates issued by the Apache Software Foundation and its community maintainers. It allows security professionals to understand the evolution of specific weakness classes within the context of this widely used gateway solution. Furthermore, the resource serves as a lookup tool for analyzing the product’s vulnerability history, helping teams assess risk exposure and prioritize patching efforts based on past incident patterns. The information is organized to facilitate quick identification of known issues without requiring manual searches across multiple external databases. This approach supports more informed decision-making for organizations relying on Apache APISIX for their infrastructure. The content is curated to reflect verified reports and officially acknowledged vulnerabilities, providing a reliable baseline for security auditing and compliance reviews. Users can navigate through the detailed entries to gain insights into remediation steps and affected versions. This structured presentation aims to enhance transparency and support proactive security management within the Apache APISIX ecosystem.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-49872 Apache APISIX: Improper authentication in cas-auth plugin CWE-287--2026-06-19
CVE-2026-49871 Apache APISIX: cas-auth login CSRF / session injection issue CWE-352--2026-06-19
CVE-2026-47341 Apache APISIX: Session replay issue in hmac-auth CWE-294--2026-06-19
CVE-2026-48895 Apache APISIX: Cas-auth Host header influence on CAS service URL CWE-601--2026-06-19
CVE-2026-49231 Apache APISIX: Identity spoofing issue in APISIX opa plugin CWE-290--2026-06-19
CVE-2026-49230 Apache APISIX: Authentication bypass in jwe-decrypt CWE-354--2026-06-19
CVE-2026-44915 Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value CWE-601--2026-06-19
CVE-2026-44087 Apache APISIX: Openid-connect plugin Identity Header Spoofing CWE-345--2026-06-19
CVE-2026-47339 Apache APISIX: authz-casdoor incorrect session sharing CWE-863--2026-06-19
CVE-2026-44046 Apache APISIX: wolf-rbac plugin Identity Spoofing CWE-348--2026-06-19
CVE-2026-39999 Apache APISIX: JWT Algorithm Confusion allows authentication bypass CWE-290--2026-06-19
CVE-2026-39998 Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup CWE-20--2026-06-19
CVE-2026-31923 Apache APISIX: Openid-connect `tls_verify` field is disabled by default CWE-319 7.5 -2026-04-14
CVE-2026-31924 Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP CWE-319 7.5 -2026-04-14
CVE-2026-31908 Apache APISIX: forward auth plugin allows header injection CWE-75 8.2 -2026-04-14
CVE-2025-62232 Apache APISIX: basic-auth logs plaintext credentials at info level CWE-532 6.5 -2025-10-31
CVE-2025-46647 Apache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connect CWE-302 7.5AIHighAI2025-07-02
CVE-2024-32638 Apache APISIX: Forward-Auth Request Smuggling CWE-444 9.1 -2024-05-02
CVE-2022-29266 apisix/jwt-auth may leak secrets in error response CWE-209 7.5 -2022-04-20
CVE-2022-25757 Apache APISIX: the body_schema check in request-validation plugin can be bypassed CWE-20 9.8 -2022-03-28
CVE-2022-24112 apisix/batch-requests plugin allows overwriting the X-REAL-IP header CWE-290 9.8 -2022-02-11
CVE-2021-43557 Path traversal in request_uri variable 9.1 -2021-11-22
CVE-2020-13945 Apache Apisix 安全漏洞 6.5 -2020-12-07

All 23 known CVE vulnerabilities affecting Apache APISIX with full Chinese analysis, references, and POCs where available.