Cleartext transmission of sensitive information in Apache APISIX - CVE-2026-31923
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to cleartext transmission of sensitive information in the openid-connect plugin configuration when handling OpenID Connect connections with certificate verification disabled by default. A remote attacker can intercept network traffic to disclose sensitive information.