Known vulnerabilities in Apache APISIX 3.16.1
Vendor:
Apache Foundation
Software:
Apache APISIX
Version:
3.16.1
Software CPE:
cpe:2.3:a:apache_foundation:apisix:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
3.16.1
3.18.0
3.17.0
3.16.0
3.15.0
3.14.1
3.14.0
3.13.0
3.12.0
3.11.0
3.10.0
3.9.1
3.8.1
3.9.0
3.8.0
3.7.0
3.6.0
3.5.0
3.2.2
3.4.1
3.4.0
3.2.1
3.3.0
2.15.3
3.2.0
2.15.2
3.1.0
2.15.1
3.0.0
2.99.0
2.13.3
2.15.0
2.13.2
2.14.1
2.14.0
2.13.1
2.10.5
2.13.0
2.10.4
2.12.1
2.12.0
2.10.3
2.11.0
2.10.2
2.10.1
2.10.0
2.9
2.8
2.7
2.6
2.5
2.4
2.3
2.2
2.1
2.0
1.5
1.4.1
1.4
1.3
1.2
1.1
1.0
0.9
0.8
0.7
0.5
0.4.1
0.4
0.3
0.2
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145878 - Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') CVE-2026-75020 |
CWE-90 | Low | 3.18.0 | 27.08.2026 |
SB2026082617 |
||
| #VU145876 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-74848 |
CWE-444 | Medium | 3.18.0 | 27.08.2026 |
SB2026082617 |
||
| #VU145389 - Reliance on Untrusted Inputs in a Security Decision CVE-2026-63041 |
CWE-807 | High | 3.18.0 | 26.08.2026 |
SB2026082617 |