CVE-2026-94269: Apache APISIX: Servlet-style normalization creates a route/upstream authorization mismatch
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX.
In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been rejected is served instead, giving unauthenticated access to a protected upstream endpoint. This issue affects Apache APISIX: from 2.14.1 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache APISIXto a version that resolves this vulnerability.Fixed in 3.19.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Apache APISIX versions 2.14.1 through 3.18.0 are affected when a permissive route overlaps a protected route. The issue is configuration-dependent; the provided information does not state that all default configurations are affected.
What does an attacker need to exploit this issue?
An attacker needs an APISIX deployment with the relevant overlapping route configuration and must send a crafted encoded path. Successful exploitation can provide unauthenticated access to a protected upstream endpoint.
How can I determine whether my deployment needs remediation?
Check whether the APISIX version is in the affected range and review routes for permissive routes that overlap protected routes. Upgrade to APISIX 3.19.0, which fixes the issue.