Where
-Infinity
0

Apache APISIXApache APISIX: Improper authentication in cas-auth plugin

Risk 63
Severity
5.3
First published (updated )

Apache APISIXApache APISIX: cas-auth login CSRF / session injection issue

Risk 69
Severity
2.1
First published (updated )

Apache APISIXApache APISIX: Session replay issue in hmac-auth

Risk 42
Severity
6.3
First published (updated )

Apache APISIXApache APISIX: Cas-auth Host header influence on CAS service URL

Risk 46
Severity
2.1
First published (updated )

Apache APISIXApache APISIX: Identity spoofing issue in APISIX opa plugin

Risk 36
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache APISIXApache APISIX: Authentication bypass in jwe-decrypt

Risk 70
Severity
6.3
First published (updated )

Apache APISIXApache APISIX: Cas-auth plugin open redirect via unsanitized cookie value

Risk 40
Severity
2.1
First published (updated )

Apache APISIXApache APISIX: Openid-connect plugin Identity Header Spoofing

Risk 70
Severity
5.3
First published (updated )

Apache APISIXApache APISIX: authz-casdoor incorrect session sharing

Risk 63
Severity
5.3
First published (updated )

Apache Apache APISIXApache APISIX: wolf-rbac plugin Identity Spoofing

Risk 31
Severity
2.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache APISIXApache APISIX: JWT Algorithm Confusion allows authentication bypass

Risk 70
Severity
7
First published (updated )

Apache APISIXApache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup

Risk 83
Severity
5.8
First published (updated )

oss-secCVE-2026-48895: Apache APISIX: Cas-auth Host header influence on CAS service URL

oss-secCVE-2026-49230: Apache APISIX: Authentication bypass in jwe-decrypt

oss-secCVE-2026-49231: Apache APISIX: Identity spoofing issue in APISIX opa plugin

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-49871: Apache APISIX: cas-auth login CSRF / session injection issue

oss-secCVE-2026-49872: Apache APISIX: Improper authentication in cas-auth plugin

oss-secCVE-2026-47339: Apache APISIX: authz-casdoor incorct session sharing

oss-secCVE-2026-44915: Apache APISIX: Cas-auth plugin open dict via unsanitized cookie value

oss-secCVE-2026-44087: Apache APISIX: Openid-connect plugin Identity Header Spoofing

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-44046: Apache APISIX: wolf-rbac plugin Identity Spoofing

oss-secCVE-2026-39999: Apache APISIX: JWT Algorithm Confusion allows authentication bypass

oss-secCVE-2026-39998: Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup

Apache Apache APISIXApache APISIX: forward auth plugin allows header injection

Risk 70
Severity
9.1
First published (updated )

Apache APISIXApache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP

Risk 30
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Apache APISIXApache APISIX: Openid-connect `tls_verify` field is disabled by default

Risk 46
Severity
7.5
First published (updated )

oss-secCVE-2026-31908: Apache APISIX: forward auth plugin allows header injection

oss-secCVE-2026-31924: Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP

Apache APISIX Java Plugin RunnerApache APISIX Java Plugin Runner: Local listening file permissions in APISIX plugin runner allow a local attacker to elevate privileges

Risk 74
Severity
7.8
First published (updated )

CVE-2024-32638: Apache APISIX: Forward-Auth Request Smuggling

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203