Unrated severityNVD Advisory· Published Jun 19, 2026· Updated Jun 19, 2026
Apache APISIX: JWT Algorithm Confusion allows authentication bypass
CVE-2026-39999
Description
Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0.
Users are recommended to upgrade to version v3.17.0, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- lists.apache.org/thread/nfopt8cnxd3k0rs1oxtr7lzxrdw4mojqmitrevendor-advisory
News mentions
0No linked articles in our index yet.