CVE 5.3 MEDIUM

Apache APISIX: Openid-connect plugin Identity Header Spoofing_CVE-2026-44087

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Description

Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.

The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity headers allowing the attacker to get unauthorized access the protected resources.
This issue affects Apache APISIX: from 2.3 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Basic Information

ID CVE-2026-44087
Source apache
Published Jun 19, 2026 at 13:11

Affected Product

Vendor Apache Software Foundation
Product Apache APISIX
Version 2.3
Affected Versions Apache Software Foundation Apache APISIX 2.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.