Open redirect in Apache APISIX - CVE-2026-48895
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to an open redirect in the cas-auth component when processing manipulated client headers. A remote attacker can manipulate client headers to redirect users to an untrusted site.
The issue could potentially expose a session token.