CVE-2026-78242: Apache APISIX: data-mask may fail to redact request headers in logger output
Insertion of sensitive information into log file vulnerability in Apache APISIX.
This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure.
This issue affects Apache APISIX: 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.18.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache APISIX version 3.17.0 is affected. The issue occurs when APISIX data masking is used and a certain response structure causes a request header value to be written to the configured log sink without redaction.
What information could be exposed?
Sensitive values contained in request headers may be recorded in log output without masking. Exposure is limited to parties or systems able to access the affected log sink.
What is the remediation?
Upgrade Apache APISIX to version 3.18.0, which fixes the issue.