https://seclists.org/oss-sec/2026/q2/126: CVE-2026-31924: Apache APISIX: Plugin tencent-cloud-cls log export uses plaintext HTTP
Published Apr 14, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=2.99.0<=3.15.0
Frequently Asked Questions
1
What is the severity of CVE-2026-31924?
The severity of CVE-2026-31924 is classified as moderate.
2
Which versions of Apache APISIX are affected by CVE-2026-31924?
CVE-2026-31924 affects Apache APISIX versions from 2.99.0 through 3.15.0.
3
What type of vulnerability is CVE-2026-31924?
CVE-2026-31924 is a Cleartext Transmission of Sensitive Information vulnerability.
4
How do I fix CVE-2026-31924?
To fix CVE-2026-31924, users should configure the tencent-cloud-cls log export to use secure protocols instead of plaintext HTTP.
5
What is the impact of CVE-2026-31924 on Apache APISIX?
The impact of CVE-2026-31924 involves the potential exposure of sensitive information during log export due to the use of plaintext HTTP.