Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jv22-34xc-w9x6

Опубликовано: 14 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Header injection vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.

Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Header injection vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.

Users are recommended to upgrade to version 3.16.0, which fixes the issue.

EPSS

Процентиль: 41%
0.00521
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-75

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

CVSS3: 9.1
fstec
4 месяца назад

Уязвимость плагина forward-auth облачного API-шлюза Apache APISIX, позволяющая нарушителю обойти существующие механизмы безопасности и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 41%
0.00521
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-75