CVE-2026-39998: Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup
Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers. This issue affects Apache APISIX: from 2.12.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39998?
CVE-2026-39998 has a severity rating of medium with a CVSS score of 5.8.
How do I fix CVE-2026-39998?
To fix CVE-2026-39998, users should upgrade Apache APISIX to version 3.17.0 or later.
What type of vulnerability is CVE-2026-39998?
CVE-2026-39998 is an improper input validation vulnerability that allows identity header spoofing.
Which versions of Apache APISIX are affected by CVE-2026-39998?
CVE-2026-39998 affects Apache APISIX versions from 2.12.0 through 3.16.0.
Can CVE-2026-39998 affect the security of my applications?
Yes, CVE-2026-39998 can compromise the security of applications by allowing attackers to spoof identity headers.