PT-2026-32603 · Apache+1 · Apache Apisix+1

Oleh Konko

·

Published

2026-04-14

·

Updated

2026-04-16

·

CVE-2026-31924

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache APISIX versions 2.99.0 through 3.15.0
Description The tencent-cloud-cls log export feature transmits sensitive information using plaintext HTTP, which allows the data to be sent without encryption.
Recommendations Upgrade to version 3.16.0.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-APISIX-2026-31924
CVE-2026-31924

Affected Products

Apache Apisix
Apisix