High severityNVD Advisory· Published Aug 27, 2026
CVE-2026-74848
CVE-2026-74848
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX.
An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes.
This issue affects Apache APISIX: from 2.12.0 through 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.