Input validation error in Apache APISIX - CVE-2026-39998
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof identity headers.
The vulnerability exists due to improper input validation in the forward-auth plugin when processing requests under certain configurations. A remote attacker can send crafted headers to spoof identity headers.
Exploitation is possible only when the forward-auth plugin is used with certain configurations.