Improper Neutralization of Special Elements in Output Used by a Downstream Component in Apache APISIX - CVE-2026-31908
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject malicious headers.
The vulnerability exists due to improper neutralization of input in the forward-auth plugin when processing certain configurations. A remote attacker can supply crafted header values to inject malicious headers.
Exploitation depends on certain forward-auth plugin configurations.