Apisix
Vendor:
First CVE: Dec 7, 2020 · Active for 5 years
25
Total CVEs
More Total CVEs than 95% of tracked products
3.6
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
8.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Apisix over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2020
5 years ago
Most Recent CVE
Jun 19, 2026
35 days ago
CVE Severity & Scoring
Apisix25 CVEs
32%
40%
28%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.0%)
Network24 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None23 (92.0%)
Unknown0 (0.0%)
Required2 (8.0%)
Privileges Required
Low8 (32.0%)
High0 (0.0%)
None17 (68.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24112CRITICAL An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulne | Feb 11, 2022 | 9.8 | 99 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2020-13945MEDIUM In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. T | Dec 7, 2020 | 6.5 | 76 | NO | YES |
CVE-2026-39999CRITICAL Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin.
This | Jun 19, 2026 | 9.1 | 40 | NO | NO |
CVE-2026-49871CRITICAL Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This defect allows a remote attacker that manages to send a victim to a webpag | Jun 19, 2026 | 9.3 | 37 | NO | NO |
CVE-2026-44087CRITICAL Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin under default configuration has an attack surface that allows the attacker | Jun 19, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-49230CRITICAL Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.
This issue | Jun 19, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-39998HIGH Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers.
This issue aff | Jun 19, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-49872HIGH Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different | Jun 19, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-47339HIGH Incorrect Authorization vulnerability in Apache APISIX.
An attacker can capitalise on authz-casdoor plugin under default configuration to authenticate themselves with credentials | Jun 19, 2026 | 8.1 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
2 CVEs
8.0% of CVEs· 97th percentile
Metasploit
2 CVEs
8.0% of CVEs· 97th percentile
Nuclei
2 CVEs
8.0% of CVEs· 97th percentile
ExploitDB
2 CVEs
8.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Apisix
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.9.0 | 1 | 6.3 | 1.1% | 0 | 0 |
| 3.8.0 | 1 | 6.3 | 1.1% | 0 | 0 |