PT-2026-32601 · Apache · Apache Apisix
Seungmyung Lee
·
Published
2026-04-14
·
Updated
2026-04-16
·
CVE-2026-31908
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apache APISIX versions 2.12.0 through 3.15.0
Description
A header injection issue exists in the forward-auth plugin due to improper neutralization of CRLF sequences (Carriage Return Line Feed, a special sequence of characters used to mark the end of a line of text). A remote attacker can exploit this by sending specially crafted HTTP requests to inject malicious headers, potentially bypassing security mechanisms and gaining unauthorized access to protected information.
Recommendations
Upgrade to version 3.16.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Apisix