CVE-2026-31924: Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP
Published Apr 14, 2026
·Updated
Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.
tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0.
Users are recommended to upgrade to version 3.16.0, which fixes the issue.
Affected Software
2 affected components
Apache APISIX>=2.99.0<=3.15.0
Apache APISIX>=2.99.0<3.16.0
Event History
Apr 14, 2026
CVE Published
via MITRE·08:08 AM
Data Sourced
via MITRE·08:08 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31924?
CVE-2026-31924 has a medium severity due to the risk of plaintext transmission of sensitive information.
2
How do I fix CVE-2026-31924?
To fix CVE-2026-31924, users should upgrade Apache APISIX to version 3.15.1 or later.
3
What versions of Apache APISIX are affected by CVE-2026-31924?
CVE-2026-31924 affects Apache APISIX versions from 2.99.0 up to 3.15.0.
4
What is the main problem caused by CVE-2026-31924?
The main problem caused by CVE-2026-31924 is the use of plaintext HTTP which can expose sensitive information.
5
What component of Apache APISIX does CVE-2026-31924 involve?
CVE-2026-31924 involves the tencent-cloud-cls log export plugin in Apache APISIX.