Rate Limit Bypass in Higress Plugin due to Malformed Cookie Handling
CVE-2026-92790
6.9MEDIUM
What is CVE-2026-92790?
The Higress plugin versions prior to 2.2.4 are susceptible to a vulnerability that allows attackers to exploit malformed Cookie header segments. This issue arises when the system processes Cookie headers missing an equals sign, leading to a panic state. Consequently, the plugin wrapper's recovery mechanism mistakenly returns a continue action, allowing unauthorized users to navigate around the AI token rate limiting. As a result, attackers can bypass rate limit enforcement mechanisms, potentially leading to excessive backend calls that could compromise service integrity.
Affected Version(s)
higress 0 < 2.2.4
