Cross-Site Request Forgery in Apache APISIX Plugins
CVE-2026-94220
2.1LOW
What is CVE-2026-94220?
A Cross-Site Request Forgery vulnerability exists in the feishu-auth and dingtalk-auth plugins within Apache APISIX. An attacker can exploit this vulnerability by enticing a user to click on a malicious link, thereby establishing a session under the attacker's identity. As a result, any actions taken by the user, such as uploads or form submissions, will be executed as if they were the attacker. This vulnerability affects versions 3.17.0 through 3.18.0, with users urged to upgrade to version 3.19.0 to mitigate the risk.
Affected Version(s)
Apache APISIX 3.17.0 <= 3.18.0
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
MopMonk-AI
shreemaan-abhishek
shreemaan-abhishek