SB2026100188 - Multiple vulnerabilities in Apache APISIX
Published: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Improper Verification of Cryptographic Signature (CVE-ID: CVE-2026-94212)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to impersonate any user.
The vulnerability exists due to improper verification of cryptographic signature in the saml-auth plugin when processing SAML authentication data. A remote user can provide SAML authentication data to impersonate any user.
Only routes protected by the saml-auth plugin under the default configuration are affected.
2) Cross-site request forgery (CVE-ID: CVE-2026-94220)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause actions performed by a victim to be attributed to the attacker's account.
The vulnerability exists due to cross-site request forgery in the feishu-auth and dingtalk-auth plugins when a user clicks a crafted link. A remote attacker can trick a user into clicking a crafted link to establish the user's browser session on a protected route under the attacker's identity.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-94250)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the batch-requests plugin when processing batch requests through a publicly exposed batch endpoint. A remote attacker can send batch requests that exhaust gateway worker memory to cause a denial of service.
4) Use of Non-Canonical URL Paths for Authorization Decisions (CVE-ID: CVE-2026-94269)
CWE-ID: CWE-647 - Use of Non-Canonical URL Paths for Authorization Decisions
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access protected upstream endpoints.
The vulnerability exists due to use of non-canonical URL paths for authorization decisions in Apache APISIX route and upstream authorization handling when processing crafted encoded paths where a permissive route overlaps a protected route. A remote attacker can send a crafted request to access protected upstream endpoints.
5) Improper Authentication (CVE-ID: CVE-2026-94276)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to gain unauthorized access to resources restricted to another issuer.
The vulnerability exists due to improper authentication in the openid-connect plugin when performing remote token introspection. A remote user can present a token active for one issuer to a route restricted to another issuer to gain unauthorized access to resources restricted to another issuer.
The authorization server must serve multiple issuers.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=1230fnojnmc7bfz3n0nkt7tkcld9d1sc
- https://apisix.apache.org
- https://lists.apache.org/api/email.lua?id=c6v0xbmr2yb5kw6325wdoh22ro6vp2d0
- https://lists.apache.org/api/email.lua?id=l7o9w8pw3w3f12vf9ybm7xtfzoo6qct4
- https://lists.apache.org/api/email.lua?id=6p7glm8jtkjrn12t7z2ybn6bplm22tns
- https://lists.apache.org/api/email.lua?id=txn3br25kl657fh15rwcy1oht1xbpyyk