CVE-2026-31908: Apache APISIX: forward auth plugin allows header injection
Published Apr 14, 2026
·Updated
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue.
Affected Software
2 affected components
Apache Apache APISIX>=2.12.0<=3.15.0
Apache APISIX>=2.12.0<3.16.0
Event History
Apr 14, 2026
CVE Published
via MITRE·08:06 AM
Data Sourced
via MITRE·08:06 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31908?
CVE-2026-31908 has a medium severity level due to the potential for unauthorized header injection.
2
How do I fix CVE-2026-31908?
To fix CVE-2026-31908, upgrade Apache APISIX to a version higher than 3.15.0.
3
What versions of Apache APISIX are affected by CVE-2026-31908?
CVE-2026-31908 affects Apache APISIX versions from 2.12.0 to 3.15.0.
4
Can CVE-2026-31908 lead to further attacks?
Yes, the header injection from CVE-2026-31908 could potentially be exploited for more serious attacks.
5
Is CVE-2026-31908 being actively exploited?
As of now, there haven't been any confirmed reports of active exploitation of CVE-2026-31908.