Allocation of Resources Without Limits or Throttling in Apache APISIX - CVE-2026-94250
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the batch-requests plugin when processing batch requests through a publicly exposed batch endpoint. A remote attacker can send batch requests that exhaust gateway worker memory to cause a denial of service.