<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache APISIX (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/apache-apisix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-apisix-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache APISIX (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-31923 – Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31923</guid>
    <pubDate>Tue, 14 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31923</strong></p>
  <p>Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.  This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0.  Users are recommended to upgrade to version 3.16.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31908 – Header injection vulnerability in Apache APISIX.

The attacker can take advantag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31908</guid>
    <pubDate>Tue, 14 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31908</strong></p>
  <p>Header injection vulnerability in Apache APISIX.  The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.  Users are recommended to upgrade to version 3.16.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27446 – Incorrect Permission Assignment for Critical Resource vulnerability in Apache AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27446</guid>
    <pubDate>Sun, 06 Jul 2025 06:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27446</strong></p>
  <p>Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner).  Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0.  Users are recommended to upgrade to version 0.6.0 or higher, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29266 – In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29266</guid>
    <pubDate>Wed, 20 Apr 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29266</strong></p>
  <p>In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-25757 – In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25757</guid>
    <pubDate>Mon, 28 Mar 2022 07:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-25757</strong></p>
  <p>In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example, `{"string_payload":"bad","string_payload":"good"}` can be used to hide the "bad" input. Systems satisfy three conditions below a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24112 – An attacker can abuse the batch-requests plugin to send requests to bypass the I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24112</guid>
    <pubDate>Fri, 11 Feb 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24112</strong></p>
  <p>An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45232 – In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45232</guid>
    <pubDate>Mon, 27 Dec 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45232</strong></p>
  <p>In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43557 – The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43557</guid>
    <pubDate>Mon, 22 Nov 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43557</strong></p>
  <p>The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43557">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
