
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-74848 is an HTTP Request/Response Smuggling vulnerability (CWE-444) in Apache APISIX, specifically affecting serverless-plugin routes. An unauthenticated attacker can manipulate HTTP requests to cause other clients to receive attacker-chosen responses or responses containing other users' sensitive data. The vulnerability affects Apache APISIX versions 2.12.0 through 3.17.0, and was publicly disclosed on August 26, 2026, with a fix available in version 3.18.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, OSS-Sec).
The root cause is an inconsistent interpretation of HTTP requests (CWE-444, CAPEC-33) within Apache APISIX's serverless-plugin route handling. When APISIX acts as an intermediary, it fails to properly parse or normalize certain malformed or ambiguous HTTP requests, allowing an attacker to craft requests that desynchronize the connection state between the gateway and backend or between the gateway and other clients. This enables response poisoning — where a victim client receives a response intended for another user, or an attacker-crafted response — without requiring any authentication or user interaction. The attack does require specific deployment conditions (Attack Requirements: Present in CVSS v4.0), meaning the serverless-plugin must be active on the targeted routes (GitHub Advisory, OSS-Sec).
Successful exploitation allows an unauthenticated network attacker to poison HTTP responses on serverless-plugin routes, causing other clients to receive attacker-chosen content or responses containing other users' sensitive data. The primary impact is on integrity and confidentiality of subsequent systems (rated High in CVSS v4.0), as session data, authentication tokens, or private API responses could be exposed to or replaced by attacker-controlled content. Availability of the vulnerable APISIX instance itself is not directly impacted, but the cross-user data leakage poses significant privacy and trust risks in multi-tenant or API gateway deployments (GitHub Advisory, OSS-Sec).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported by security researcher Xclow3n (Rajat Raghav) (OSS-Sec). The EPSS score is approximately 0.45–0.62%, placing it in roughly the 48th percentile for exploitation probability within 30 days. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" at this time.
Content-Length and Transfer-Encoding headers, or malformed chunked encoding, to desynchronize the connection state.Content-Length and Transfer-Encoding headers; requests with malformed chunked encoding targeting the same route in rapid succession.The primary remediation is to upgrade Apache APISIX to version 3.18.0 or later, which contains the fix for this vulnerability (OSS-Sec, GitHub Advisory). If immediate patching is not feasible, organizations should restrict network access to APISIX instances and disable or limit the use of serverless-plugin routes where possible. Additionally, deploying a WAF or reverse proxy with HTTP request normalization in front of APISIX can help detect and block smuggling attempts as a temporary mitigation (Apache Advisory).
The vulnerability was disclosed via the Apache security mailing list and the oss-security list by Abhishek Choudhary on behalf of Apache, crediting researcher Xclow3n (Rajat Raghav) as the reporter (OSS-Sec). The advisory was picked up by standard vulnerability aggregators including VulDB, OSV, and CIRCL shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."