CVE-2026-31908

CVE-2026-31908: Apache APISIX: forward auth plugin allows header injection

Vendor Apache Software Foundation
Product Apache APISIX
Weakness CWE-75
Published April 14, 2026
Last update April 16, 2026

CVSS base score

What the vulnerability does

Description

Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Key dates

Disclosure timeline

April 14, 2026 CVE published
April 16, 2026 Record updated