Exposição de Apache APISIX

Web servers
66
score de exposição
1.477
sites usam
1
em exploração
2
críticos
Análise Vexday

Apache APISIX apresenta uma taxa de exploração ativa 9,7 vezes acima da média geral do catálogo CISA KEV, o que indica risco operacional elevado apesar do volume total de 23 CVEs catalogadas. A CVE-2022-24112, com escore EPSS de 0,9618, concentra a ameaça mais imediata — trata-se da vulnerabilidade confirmada em exploração ativa e cuja probabilidade de exploração está entre as mais altas mensuráveis pela métrica. O tipo de falha mais recorrente, CWE-290 (Authentication Bypass by Spoofing), sugere fragilidades arquiteturais na camada de autenticação que podem ser encadeadas com outras falhas. O surgimento de 15 CVEs nos últimos 90 dias merece atenção redobrada, pois indica aumento recente de superfície de ataque e exige priorização imediata de ciclos de patching em ambientes que expõem o APISIX a redes não confiáveis.

CVEs

23 resultados
CVE-2022-24112CRITICALapisix/batch-requests plugin allows overwriting the X-REAL-IP headerEPSS 96.0%KEVCVE-2020-13945In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allEPSS 73.0%CVE-2021-43557Path traversal in request_uri variableEPSS 14.6%CVE-2022-29266apisix/jwt-auth may leak secrets in error responseEPSS 7.8%CVE-2022-25757Apache APISIX: the body_schema check in request-validation plugin can be bypassedEPSS 2.4%CVE-2024-32638MEDIUMApache APISIX: Forward-Auth Request SmugglingEPSS 1.1%CVE-2026-31908CRITICALApache APISIX: forward auth plugin allows header injectionEPSS 0.5%CVE-2025-62232HIGHApache APISIX: basic-auth logs plaintext credentials at info levelEPSS 0.4%CVE-2026-47341MEDIUMApache APISIX: Session replay issue in hmac-authEPSS 0.4%CVE-2026-39999HIGHApache APISIX: JWT Algorithm Confusion allows authentication bypassEPSS 0.4%CVE-2025-46647MEDIUMApache APISIX: improper validation of issuer from introspection discovery url in plugin openid-connectEPSS 0.4%CVE-2026-48895LOWApache APISIX: Cas-auth Host header influence on CAS service URLEPSS 0.4%CVE-2026-39998MEDIUMApache APISIX: Identity Injection via forward-auth Plugin Missing Header CleanupEPSS 0.4%CVE-2026-44915LOWApache APISIX: Cas-auth plugin open redirect via unsanitized cookie valueEPSS 0.4%CVE-2026-49231LOWApache APISIX: Identity spoofing issue in APISIX opa pluginEPSS 0.4%CVE-2026-49872MEDIUMApache APISIX: Improper authentication in cas-auth pluginEPSS 0.3%CVE-2026-44046LOWApache APISIX: wolf-rbac plugin Identity SpoofingEPSS 0.3%CVE-2026-47339MEDIUMApache APISIX: authz-casdoor incorrect session sharingEPSS 0.3%CVE-2026-49871LOWApache APISIX: cas-auth login CSRF / session injection issueEPSS 0.3%CVE-2026-31923HIGHApache APISIX: Openid-connect `tls_verify` field is disabled by defaultEPSS 0.3%