Open redirect in Apache APISIX - CVE-2026-44915
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to open redirect in the cas-auth plugin when processing an unsanitized cookie value. A remote attacker can supply a crafted cookie value to redirect users to an untrusted site.
The default configuration of the cas-auth plugin is vulnerable, which may enable phishing and credential theft.