CVE-2026-31908CWE-75

Apache APISIX: forward auth plugin allows header injection

Critical · published April 14, 2026

CVSS v3.1
9.1
EPSS
1%
Percentile
42.4
In the wild
Unconfirmed
What it is

Header injection vulnerability in Apache APISIX.

The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.

This issue affects Apache APISIX: from 2.12.0 through 3.15.0.

Users are recommended to upgrade to version 3.16.0, which fixes the issue.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00521 · 42.4th percentile
Weakness
CWE-75 · Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
Published
2026-04-14T08:06Z
EPSS history
Timeline
  • 14 APR 08:06Z
    Apache APISIX: forward auth plugin allows header injection
    cvelistv5