<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache APISIX</title>
  <link>https://cvedaily.com/pages/tags/apache-apisix.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-apisix.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache APISIX</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-31924 – Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31924</guid>
    <pubDate>Tue, 14 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31924</strong></p>
  <p>Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.  tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0.  Users are recommended to upgrade to version 3.16.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31923 – Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31923</guid>
    <pubDate>Tue, 14 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31923</strong></p>
  <p>Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.  This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0.  Users are recommended to upgrade to version 3.16.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31908 – Header injection vulnerability in Apache APISIX.

The attacker can take advantag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31908</guid>
    <pubDate>Tue, 14 Apr 2026 09:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31908</strong></p>
  <p>Header injection vulnerability in Apache APISIX.  The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.  Users are recommended to upgrade to version 3.16.0, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-75</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27446 – Incorrect Permission Assignment for Critical Resource vulnerability in Apache AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27446</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27446</guid>
    <pubDate>Sun, 06 Jul 2025 06:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27446</strong></p>
  <p>Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner).  Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges. This issue affects Apache APISIX(java-plugin-runner): from 0.2.0 through 0.5.0.  Users are recommended to upgrade to version 0.6.0 or higher, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27446">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46647 – A vulnerability of plugin openid-connect in Apache APISIX.

This vulnerability w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46647</guid>
    <pubDate>Wed, 02 Jul 2025 12:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46647</strong></p>
  <p>A vulnerability of plugin openid-connect in Apache APISIX.  This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different  If affected by…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-302</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32638 – Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32638</guid>
    <pubDate>Thu, 02 May 2024 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32638</strong></p>
  <p>Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.  Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32638">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29266 – In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that le...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29266</guid>
    <pubDate>Wed, 20 Apr 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29266</strong></p>
  <p>In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-25757 – In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjso...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25757</guid>
    <pubDate>Mon, 28 Mar 2022 07:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-25757</strong></p>
  <p>In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example, `{"string_payload":"bad","string_payload":"good"}` can be used to hide the "bad" input. Systems satisfy three conditions below a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24112 – An attacker can abuse the batch-requests plugin to send requests to bypass the I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24112</guid>
    <pubDate>Fri, 11 Feb 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24112</strong></p>
  <p>An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-45232 – In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45232</guid>
    <pubDate>Mon, 27 Dec 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-45232</strong></p>
  <p>In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43557 – The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43557</guid>
    <pubDate>Mon, 22 Nov 2021 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43557</strong></p>
  <p>The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same i…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33190 – In Apache APISIX Dashboard version 2.6, we changed the default value of listen h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33190</guid>
    <pubDate>Tue, 08 Jun 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33190</strong></p>
  <p>In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time, the default account and password are fixed.Ultimately these factors lead to the i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13945 – In Apache APISIX, the user enabled the Admin API and deleted the Admin API acces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13945</guid>
    <pubDate>Mon, 07 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13945</strong></p>
  <p>In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13945">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
