Cross-Site Request Forgery in Apache APISIX Plugins
CVE-2026-94220

2.1LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94220?

A Cross-Site Request Forgery vulnerability exists in the feishu-auth and dingtalk-auth plugins within Apache APISIX. An attacker can exploit this vulnerability by enticing a user to click on a malicious link, thereby establishing a session under the attacker's identity. As a result, any actions taken by the user, such as uploads or form submissions, will be executed as if they were the attacker. This vulnerability affects versions 3.17.0 through 3.18.0, with users urged to upgrade to version 3.19.0 to mitigate the risk.

Affected Version(s)

Apache APISIX 3.17.0 <= 3.18.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk-AI
shreemaan-abhishek
shreemaan-abhishek
.