https://seclists.org/oss-sec/2026/q2/127: CVE-2026-31908: Apache APISIX: forward auth plugin allows header injection
Published Apr 14, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=2.12.0<=3.15.0
Frequently Asked Questions
1
What is the severity of CVE-2026-31908?
The severity of CVE-2026-31908 is classified as moderate.
2
Which versions of Apache APISIX are affected by CVE-2026-31908?
CVE-2026-31908 affects Apache APISIX versions from 2.12.0 through 3.15.0.
3
What type of vulnerability is CVE-2026-31908?
CVE-2026-31908 is a header injection vulnerability in the forward auth plugin of Apache APISIX.
4
How can CVE-2026-31908 be exploited?
An attacker can exploit CVE-2026-31908 by taking advantage of specific configurations in the forward-auth plugin to inject malicious headers.
5
How do I fix CVE-2026-31908?
To mitigate CVE-2026-31908, upgrade to a version of Apache APISIX that is above 3.15.0.