Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63041

Опубликовано: 26 авг. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.

This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.

This issue affects Apache APISIX: from 3.11.0 through 3.17.0.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:*
Версия от 3.11.0 (включая) до 3.18.0 (исключая)

EPSS

Процентиль: 51%
0.00677
Низкий

8.8 High

CVSS3

Дефекты

CWE-807

Связанные уязвимости

CVSS3: 8.8
github
26 дней назад

Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

EPSS

Процентиль: 51%
0.00677
Низкий

8.8 High

CVSS3

Дефекты

CWE-807