Resource Allocation Vulnerability in Batch-Requests Plugin of Apache APISIX
CVE-2026-94250

8.2HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94250?

A resource allocation vulnerability exists in the batch-requests plugin for Apache APISIX. This issue allows an unauthenticated user to cause a denial of service by driving a gateway worker to out-of-memory (OOM) state. It occurs when the batch endpoint is publicly accessible, permitting excessive resource consumption. To mitigate this vulnerability, it is crucial for users to upgrade to Apache APISIX version 3.19.0 or later, where the issue is resolved.

Affected Version(s)

Apache APISIX 1.3.0 <= 3.18.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ziyue
shreemaan-abhishek
shreemaan-abhishek
.