Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86hq-f9pp-3cr9

Опубликовано: 19 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.8
CVSS3: 8.8

Описание

Improper Input Validation vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Improper Input Validation vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

EPSS

Процентиль: 33%
0.00403
Низкий

5.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.

CVSS3: 8.8
fstec
около 2 месяцев назад

Уязвимость плагина forward-auth облачного API-шлюза Apache APISIX, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 33%
0.00403
Низкий

5.8 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-20