Vulnerability in OpenID Connect Plugin for Apache APISIX
CVE-2025-46647
What is CVE-2025-46647?
A vulnerability exists in the OpenID Connect plugin for Apache APISIX where, under specific conditions, an attacker with valid credentials from one issuer can gain unauthorized access to services associated with another issuer. This occurs when the plugin is used in introspection mode, multiple issuers share the same private key, and the auth service is configured to serve multiple issuers without proper separation. It is crucial for users of Apache APISIX to upgrade to version 3.12.0 or higher to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache APISIX 0 < 3.12.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved