CVE-2026-31923

CVE-2026-31923: Apache APISIX: Openid-connect `tls_verify` field is disabled by default

Vendor Apache Software Foundation
Product Apache APISIX
Weakness CWE-319 · Cleartext transmission
Published April 14, 2026
Last update April 14, 2026

CVSS base score

What the vulnerability does

Description

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Key dates

Disclosure timeline

April 14, 2026 CVE published
April 14, 2026 Record updated