CVE-2026-31908CWE-75
Apache APISIX: forward auth plugin allows header injection
Critical · published April 14, 2026
What it is
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.
This issue affects Apache APISIX: from 2.12.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue.
The record
Technical detail
- CVSS v3.1
- 9.1 · CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00521 · 42.4th percentile
- Weakness
- CWE-75 · Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
- Published
- 2026-04-14T08:06Z
EPSS history
Timeline