https://seclists.org/oss-sec/2026/q2/979: CVE-2026-48895: Apache APISIX: Cas-auth Host header influence on CAS service URL
Published Jun 19, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=3.0.0<=3.16.0
Frequently Asked Questions
1
What is the severity of CVE-2026-48895?
CVE-2026-48895 is classified as a vulnerability that can lead to URL redirection to untrusted sites, posing a security risk.
2
How do I fix CVE-2026-48895?
To fix CVE-2026-48895, it is recommended to update Apache APISIX to the latest version beyond 3.16.0.
3
What versions of Apache APISIX are affected by CVE-2026-48895?
CVE-2026-48895 affects Apache APISIX versions 3.0.0 through 3.16.0.
4
What kind of attack does CVE-2026-48895 enable?
CVE-2026-48895 enables an open redirect attack that could potentially expose sensitive session tokens for users.
5
Is CVE-2026-48895 a remote exploitation vulnerability?
Yes, CVE-2026-48895 can be exploited remotely by manipulating client headers.