Reliance on Untrusted Inputs in a Security Decision in Apache APISIX - CVE-2026-63041
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges or perform an authorization bypass.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the attach-consumer-label plugin when handling client-supplied consumer-label headers. A remote attacker can send certain header values to escalate privileges or perform an authorization bypass.