Resource Allocation Vulnerability in Batch-Requests Plugin of Apache APISIX
CVE-2026-94250
8.2HIGH
What is CVE-2026-94250?
A resource allocation vulnerability exists in the batch-requests plugin for Apache APISIX. This issue allows an unauthenticated user to cause a denial of service by driving a gateway worker to out-of-memory (OOM) state. It occurs when the batch endpoint is publicly accessible, permitting excessive resource consumption. To mitigate this vulnerability, it is crucial for users to upgrade to Apache APISIX version 3.19.0 or later, where the issue is resolved.
Affected Version(s)
Apache APISIX 1.3.0 <= 3.18.0
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ziyue
shreemaan-abhishek
shreemaan-abhishek