CVE 9.1 CRITICAL

Apache APISIX: forward auth plugin allows header injection_CVE-2026-31908

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Header injection vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.
This issue affects Apache APISIX: from 2.12.0 through 3.15.0.

Users are recommended to upgrade to version 3.16.0, which fixes the issue.

AI Analysis

Header injection vulnerability in Apache APISIX's forward-auth plugin

Basic Information

ID CVE-2026-31908
Source apache
Published Apr 14, 2026 at 08:06
Modified Apr 16, 2026 at 12:06

Affected Product

Vendor Apache Software Foundation
Product Apache APISIX
Version 2.12.0
Affected Versions Apache Software Foundation Apache APISIX 2.12.0

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor Apache Software Foundation
Product Apache APISIX
Version 2.12.0-3.15.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.