https://seclists.org/oss-sec/2026/q3/590: CVE-2026-74848: Apache APISIX: Cross-user sponse poisoning in serverless plugins
Published Aug 26, 2026
·Updated
Affected Software
1 affected component
Apache APISIX>=2.12.0<=3.17.0
Frequently Asked Questions
1
Which deployments are affected?
Apache APISIX versions 2.12.0 through 3.17.0 are affected. The described impact occurs on routes using serverless plugins.
2
What can an attacker achieve?
An attacker could cause other clients on serverless-plugin routes to receive attacker-chosen responses or responses belonging to other users.
3
What should I do to remediate the issue?
Upgrade Apache APISIX to version 3.18.0, which fixes the issue.