Sensitive Information Logging Vulnerability in Apache APISIX by Apache
CVE-2026-78242

5.7MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-78242?

A vulnerability exists in Apache APISIX that allows sensitive information, specifically unmasked header values, to be logged under certain response structures. This could potentially expose confidential data stored in logs, posing a security risk. Users are advised to upgrade to version 3.18.0 to mitigate this issue effectively.

Affected Version(s)

Apache APISIX 3.17.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas SchĂĽltke
.