Apisix

Vendor:

First CVE: Dec 7, 2020 · Active for 5 years

25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
8.0%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Apisix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2020
5 years ago
Most Recent CVE
Jun 19, 2026
35 days ago

CVE Severity & Scoring

Apisix25 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (4.0%)
Network24 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None23 (92.0%)
Unknown0 (0.0%)
Required2 (8.0%)
Privileges Required
Low8 (32.0%)
High0 (0.0%)
None17 (68.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne
Feb 11, 20229.899YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. T
Dec 7, 20206.576NOYES
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This
Jun 19, 20269.140NONO
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manages to send a victim to a webpag
Jun 19, 20269.337NONO
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default configuration has an attack surface that allows the attacker
Jun 19, 20269.137NONO
Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.  This issue
Jun 19, 20269.136NONO
Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue aff
Jun 19, 20268.836NONO
Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different
Jun 19, 20268.132NONO
Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials
Jun 19, 20268.132NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
2 CVEs
8.0% of CVEs· 97th percentile
Metasploit
2 CVEs
8.0% of CVEs· 97th percentile
Nuclei
2 CVEs
8.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Apisix

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.9.016.31.1%00
3.8.016.31.1%00