Executive brief
Apache APISIX, a popular cloud-native API gateway, contains a security flaw in its OpenID Connect plugin. Under default configurations, an attacker can forge identity information to bypass security checks. This could allow unauthorized individuals to access protected internal resources or sensitive customer data.
Technical details
An Insufficient Verification of Data Authenticity vulnerability (CWE-345) exists in the Apache APISIX openid-connect plugin. Under default configurations, the plugin fails to properly validate identity headers, creating an attack surface for header spoofing. A remote attacker with low privileges can exploit this to bypass authentication mechanisms and gain unauthorized access to upstream resources. The issue affects versions 2.3 through 3.16.0 and is resolved in version 3.17.0 (or 3.16.1 as per some advisory notes).
Affected products
- Apache APISIX 2.3 through 3.16.0
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory