CRITICAL🇵🇱 Wersja polska

CVE-2026-31908

CVSS 9.1v3.1pub. 2026-04-14upd. 2026-04-17

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

🤖 AI Analysis
How it works

An attacker exploits a specific configuration of the forward-auth plugin in Apache APISIX to inject malicious HTTP headers into transmitted requests. The forward-auth plugin is responsible for delegating authorization to external services — manipulating headers at this stage may allow bypassing authentication mechanisms or substituting data passed to the backend. The vulnerability is classified as CWE-75 (improper neutralization of special characters in HTTP headers), indicating a lack of proper input data sanitization.

Impact

An attacker can compromise the confidentiality and integrity of processed requests by injecting arbitrary HTTP headers, which may lead to bypassing authorization mechanisms or manipulating data transmitted to protected backend services.

Mitigation & patch

Apache APISIX should be updated to version 3.16.0, which contains a patch eliminating the described vulnerability. Detailed information is available in the official Apache project announcement at the address indicated in the references.

Who is affected

Apache APISIX versions from 2.12.0 to 3.15.0 inclusive, using the forward-auth plugin.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Apisix

    APP
    Apache
    2.12.0 – 3.16.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-24112CRITICAL9.8⚠ KEVPL ✓same product

Apache APISIX – RCE przez obejście ograniczeń IP w batch-requests

CVE-2022-25757CRITICAL9.8PL ✓same product

Apache APISIX — pominięcie walidacji body_schema przez duplikaty kluczy JSON

CVE-2026-75005HIGH8.7same product

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway ...

CVE-2026-74848HIGH7.0same product

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISI...

CVE-2026-75020HIGH7.0same product

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache A...