Inefficient Algorithmic Complexity in Apache APISIX by Apache
CVE-2026-75005
8.7HIGH
What is CVE-2026-75005?
An inefficient algorithmic complexity vulnerability in Apache APISIX allows a minimal request to monopolize CPU resources, causing a significant performance degradation. This issue affects users running version 3.17.0, where specific routes, such as graphql-limit-count, could lead to a gateway worker being pinned at 100% CPU utilization for an extended period. To remediate this issue, users are advised to upgrade to version 3.18.0, which addresses the performance concerns and restores normal functionality.
Affected Version(s)
Apache APISIX 3.17.0