CVE-2026-47341: Apache APISIX: Session replay issue in hmac-auth
Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry. This issue affects Apache APISIX: from 3.11.0 through 3.16.0.
Users are recommended to upgrade to version 3.17.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.17.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47341?
The severity of CVE-2026-47341 is medium, with a CVSS score of 6.3.
What does CVE-2026-47341 affect?
CVE-2026-47341 affects the hmac-auth component of Apache APISIX versions from 3.11.0 through 3.16.0.
How do I fix CVE-2026-47341?
To fix CVE-2026-47341, users are recommended to upgrade to Apache APISIX version 3.17.0 or later.
What type of vulnerability is CVE-2026-47341?
CVE-2026-47341 is an Authentication Bypass by Capture-replay vulnerability.
Can CVE-2026-47341 allow an attacker to bypass tokens?
Yes, CVE-2026-47341 allows an attacker to reuse a token indefinitely, bypassing its expiry.