2
Total CVEs
0
Critical
1
High
1
Medium
0
Low

Recent CVEs

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users a...

Affected versions: 2.99.0 3.0.0 3.1.0 3.10.0 3.11.0 +18 more

Published: Apr 14, 2026

5.3

CVSS

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue aff...

Affected versions: 0.7 0.8 0.9 1.0 1.1 +55 more

Published: Apr 14, 2026

7.5

CVSS

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2....

Affected versions: 2.12.0 2.12.1 2.13.0 2.13.1 2.13.2 +29 more

Published: Apr 14, 2026

9.1

CVSS

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX plugin runner allow a local attacker to elevate pr...

Affected versions: 0.2 0.3 0.3-1 0.4.1 0.5

Published: Jul 6, 2025

7.8

CVSS

A vulnerability of plugin openid-connect in Apache APISIX. This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection...

Affected versions: 0.2 0.3 0.3-1 0.4.1 0.5 +57 more

Published: Jul 2, 2025

5.3

CVSS

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are...

Affected versions: 3.8.0 3.9.0

Published: May 2, 2024

6.3

CVSS