CVE-2026-31908 is a header injection vulnerability in Apache APISIX affecting versions 2.12.0 through 3.15.0, specifically within the forward-auth plugin configuration. Attackers can exploit this vulnerability to inject malicious headers, potentially compromising application security controls. The vendor recommends immediate upgrade to version 3.16.0 to remediate the issue. The vulnerability carries a CRITICAL CVSS score of 9.1, indicating severe risk. The attack requires no authentication or user interaction and can be executed remotely over the network with low complexity. The vulnerability poses high confidentiality and integrity impacts, though availability is not affected. This network-based attack vector makes it particularly concerning for internet-facing deployments. Exploitation status remains low at this time. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and is currently inactive on hot exploit lists. The EPSS score of 0.00122 indicates this CVE ranks higher than only 0.31 percent of all vulnerabilities in terms of exploitation probability. However, the high CVSS score and FAUCET risk assessment of 52.0 warrant prioritized patching regardless of current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.12.0, < 3.16.0CPE matchmatch criteria | cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.