VYPR

Apisix

by Apache

Source repositories

CVEs (29)

  • CVE-2026-47341MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0. Users are recommended to upgrade to…

  • CVE-2026-31923HigApr 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade…

  • CVE-2025-62232HigOct 31, 2025
    risk 0.42cvss 7.5epss 0.00

    Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access. It has been fixed in the following…

  • CVE-2024-32638MedMay 2, 2024
    risk 0.41cvss 6.3epss 0.01

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the…

  • CVE-2026-44915MedJun 19, 2026
    risk 0.40cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft. This issue affects Apache APISIX: from 3.0.0 through 3.16.0. Users are recommended to…

  • CVE-2026-44046MedJun 19, 2026
    risk 0.38cvss 5.8epss 0.00

    Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information and exploit IP based access control rules. This issue affects Apache APISIX: from…

  • CVE-2026-49231MedJun 19, 2026
    risk 0.35cvss 5.4epss 0.01

    Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin. This could allow the attacker to assume higher privileges on the upstream service. This issue…

  • CVE-2026-31924MedApr 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

  • CVE-2025-46647MedJul 2, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to…

Page 2 of 2