CVE-2026-31924
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users…
All CVEs associated with "Apache APISIX". Page 1/1 • 13 CVEs.
A curated feed of “Apache APISIX”-related CVEs appears below. We currently track 13 CVEs for this tag (all time). In the last 365 days, 5 were published. Average CVSS is 7.5 (all time; 7.0 over 365d), and 62% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-319 - Cleartext Transmission of Sensitive Information, CWE-75 - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection), CWE-732 - Incorrect Permission Assignment for Critical Resource.
In our taxonomy this topic maps to a LOW impact class. API gateways sit at the edge. Patch, enforce auth and rate limits, validate JWT and CORS, and restrict admin APIs. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 3.16 | 3.16.0 | - | ||
| 3.15 | 3.15.0 | Expired | ||
| 3.14 | 3.14.1 | Expired | ||
| 3.13 | 3.13.0 | Expired | ||
| 3.12 | 3.12.0 | Expired | ||
| 3.11 | 3.11.0 | Expired | ||
| 3.10 | 3.10.0 | Expired | ||
| 3.9 | 3.9.1 | Expired | ||
| 3.8 | 3.8.1 | Expired | ||
| 3.7 | 3.7.0 | Expired | ||
| 3.6 | 3.6.0 | Expired | ||
| 3.5 | 3.5.0 | Expired | ||
| 3.4 | 3.4.1 | Expired | ||
| 3.3 | 3.3.0 | Expired | ||
| 3.2 | 3.2.2 | Expired | LTS | |
| 3.1 | 3.1.0 | Expired | ||
| 3.0 | 3.0.0 | Expired | ||
| 2.15 | 2.15.3 | Expired | LTS | |
| 2.14 | 2.14.1 | Expired | ||
| 2.13 | 2.13.3 | Expired | LTS | |
| 2.12 | 2.12.1 | Expired | ||
| 2.11 | 2.11.0 | Expired | ||
| 2.10 | 2.10.5 | Expired | LTS |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Apache APISIX” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users…
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue af…
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2…
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate p…
A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection…
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are…
In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive infor…
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass th…
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote cod…
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed…
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construc…
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a…
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects version…