CVE-2026-31923: Apache APISIX: Openid-connect `tls_verify` field is disabled by default
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
This can occur due to sslverify in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31923?
CVE-2026-31923 has a high severity rating of 7.5 according to the CVSS 3.1 score.
How does CVE-2026-31923 affect Apache APISIX?
CVE-2026-31923 affects Apache APISIX due to the `tls_verify` field in the openid-connect plugin being disabled by default, leading to potential cleartext transmission of sensitive information.
How do I fix CVE-2026-31923?
To fix CVE-2026-31923, users should upgrade Apache APISIX to version 3.16.0 or later.
Which versions of Apache APISIX are affected by CVE-2026-31923?
CVE-2026-31923 affects Apache APISIX versions from 0.7 through 3.15.0.
What kind of vulnerability is described in CVE-2026-31923?
CVE-2026-31923 describes a cleartext transmission of sensitive information vulnerability.