CVE-2026-44915: Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The default configuration of cas-auth in Apache APISIX is vulnerable to phishing and credential theft.
This issue affects Apache APISIX: from 3.0.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIX (cas-auth plugin)to a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44915?
CVE-2026-44915 is classified as a low severity vulnerability with a CVSS score of 4.0.
How do I fix CVE-2026-44915?
To mitigate CVE-2026-44915, users should upgrade Apache APISIX to version 3.17.0 or higher.
What type of vulnerability is CVE-2026-44915?
CVE-2026-44915 is an open redirect vulnerability that allows URL redirection to untrusted sites.
What versions of Apache APISIX are affected by CVE-2026-44915?
CVE-2026-44915 affects Apache APISIX versions from 3.0.0 through 3.16.0.
What are the risks associated with CVE-2026-44915?
The risks associated with CVE-2026-44915 include potential phishing attacks and credential theft due to its exploitable nature.