Improper Input Validation in Apache APISIX Affects Identity Header Spoofing
CVE-2026-39998

5.8MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 June 2026

What is CVE-2026-39998?

The vulnerability in Apache APISIX arises from improper input validation within the forward-auth plugin, potentially enabling an attacker to spoof identity headers. This issue affects versions ranging from 2.12.0 to 3.16.0. Users are urged to upgrade to version 3.17.0 for resolution.

Affected Version(s)

Apache APISIX 2.12.0 <= 3.16.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fernando Mecozzi
.