PT-2026-32601 · Apache · Apache Apisix

Seungmyung Lee

·

Published

2026-04-14

·

Updated

2026-04-16

·

CVE-2026-31908

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 2.12.0 through 3.15.0
Description A header injection issue exists in the forward-auth plugin due to improper neutralization of CRLF sequences (Carriage Return Line Feed, a special sequence of characters used to mark the end of a line of text). A remote attacker can exploit this by sending specially crafted HTTP requests to inject malicious headers, potentially bypassing security mechanisms and gaining unauthorized access to protected information.
Recommendations Upgrade to version 3.16.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05625
BIT-APISIX-2026-31908
CVE-2026-31908

Affected Products

Apache Apisix