https://seclists.org/oss-sec/2026/q3/590: CVE-2026-74848: Apache APISIX: Cross-user sponse poisoning in serverless plugins
Published Aug 26, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=2.12.0<=3.17.0
Apache APISIX versions 2.12.0 through 3.17.0 are affected. The described impact occurs on routes using serverless plugins.
An attacker could cause other clients on serverless-plugin routes to receive attacker-chosen responses or responses belonging to other users.
Upgrade Apache APISIX to version 3.18.0, which fixes the issue.