Количество 3
Количество 3
CVE-2026-39998
Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
GHSA-86hq-f9pp-3cr9
Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue.
BDU:2026-08919
Уязвимость плагина forward-auth облачного API-шлюза Apache APISIX, позволяющая нарушителю проводить спуфинг-атаки
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-39998 Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-86hq-f9pp-3cr9 Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0. Users are recommended to upgrade to version 3.17.0, which fixes the issue. | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад | |
BDU:2026-08919 Уязвимость плагина forward-auth облачного API-шлюза Apache APISIX, позволяющая нарушителю проводить спуфинг-атаки | CVSS3: 8.8 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу