https://seclists.org/oss-sec/2026/q3/589: CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Published Aug 26, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=3.11.0<=3.17.0
Frequently Asked Questions
1
Which deployments are affected?
Apache APISIX versions 3.11.0 through 3.17.0 are affected. Exposure depends on use of the attach-consumer-label plugin.
2
What must an attacker do to exploit this issue?
An attacker must send certain client-controlled consumer-label header values that the attach-consumer-label plugin fails to sanitize correctly. Successful exploitation can lead to privilege escalation or an authorization bypass.
3
Is a fixed version available?
The advisory recommends upgrading to a fixed version, but the specific fixed version is still listed as pending.