CVE-2026-74848
Apache APISIX vulnerability analysis and mitigation

Overview

CVE-2026-74848 is an HTTP Request/Response Smuggling vulnerability (CWE-444) in Apache APISIX, specifically affecting serverless-plugin routes. An unauthenticated attacker can manipulate HTTP requests to cause other clients to receive attacker-chosen responses or responses containing other users' sensitive data. The vulnerability affects Apache APISIX versions 2.12.0 through 3.17.0, and was publicly disclosed on August 26, 2026, with a fix available in version 3.18.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, OSS-Sec).

Technical details

The root cause is an inconsistent interpretation of HTTP requests (CWE-444, CAPEC-33) within Apache APISIX's serverless-plugin route handling. When APISIX acts as an intermediary, it fails to properly parse or normalize certain malformed or ambiguous HTTP requests, allowing an attacker to craft requests that desynchronize the connection state between the gateway and backend or between the gateway and other clients. This enables response poisoning — where a victim client receives a response intended for another user, or an attacker-crafted response — without requiring any authentication or user interaction. The attack does require specific deployment conditions (Attack Requirements: Present in CVSS v4.0), meaning the serverless-plugin must be active on the targeted routes (GitHub Advisory, OSS-Sec).

Impact

Successful exploitation allows an unauthenticated network attacker to poison HTTP responses on serverless-plugin routes, causing other clients to receive attacker-chosen content or responses containing other users' sensitive data. The primary impact is on integrity and confidentiality of subsequent systems (rated High in CVSS v4.0), as session data, authentication tokens, or private API responses could be exposed to or replaced by attacker-controlled content. Availability of the vulnerable APISIX instance itself is not directly impacted, but the cross-user data leakage poses significant privacy and trust risks in multi-tenant or API gateway deployments (GitHub Advisory, OSS-Sec).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported by security researcher Xclow3n (Rajat Raghav) (OSS-Sec). The EPSS score is approximately 0.45–0.62%, placing it in roughly the 48th percentile for exploitation probability within 30 days. The CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment classifies exploitation as "none" at this time.

Exploitation steps

  1. Reconnaissance: Identify Apache APISIX deployments (versions 2.12.0–3.17.0) exposed to the network, particularly those with serverless-plugin routes enabled. Tools like Shodan or Censys can be used to find APISIX gateway instances.
  2. Identify target routes: Probe the APISIX gateway to enumerate routes that use the serverless-plugin, as the vulnerability is specific to this plugin's request handling.
  3. Craft smuggling payload: Construct an ambiguous HTTP request that exploits the inconsistent parsing between APISIX and the backend or between APISIX and other clients — for example, using conflicting Content-Length and Transfer-Encoding headers, or malformed chunked encoding, to desynchronize the connection state.
  4. Inject attacker-chosen response: Send the crafted request to the vulnerable serverless-plugin route so that the gateway's response queue is poisoned, causing the next legitimate client's request to receive the attacker's injected response or another user's response.
  5. Harvest sensitive data: Monitor or control the injected response to capture session tokens, authentication credentials, or private API data belonging to other users (GitHub Advisory, OSS-Sec).

Indicators of compromise

  • Network: Unusual HTTP requests to APISIX serverless-plugin routes containing conflicting Content-Length and Transfer-Encoding headers; requests with malformed chunked encoding targeting the same route in rapid succession.
  • Logs: APISIX access logs showing unexpected response codes or mismatched request/response pairs on serverless-plugin routes; log entries where a client receives a response body inconsistent with their request.
  • Application Behavior: User reports of receiving unexpected or other users' data from API responses; session confusion or authentication anomalies on routes backed by the serverless plugin.

Mitigation and workarounds

The primary remediation is to upgrade Apache APISIX to version 3.18.0 or later, which contains the fix for this vulnerability (OSS-Sec, GitHub Advisory). If immediate patching is not feasible, organizations should restrict network access to APISIX instances and disable or limit the use of serverless-plugin routes where possible. Additionally, deploying a WAF or reverse proxy with HTTP request normalization in front of APISIX can help detect and block smuggling attempts as a temporary mitigation (Apache Advisory).

Community reactions

The vulnerability was disclosed via the Apache security mailing list and the oss-security list by Abhishek Choudhary on behalf of Apache, crediting researcher Xclow3n (Rajat Raghav) as the reporter (OSS-Sec). The advisory was picked up by standard vulnerability aggregators including VulDB, OSV, and CIRCL shortly after disclosure. No significant independent researcher commentary or major media coverage has been identified beyond routine vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Apache APISIX vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75005HIGH8.7
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesAug 27, 2026
CVE-2026-75020HIGH7
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesAug 27, 2026
CVE-2026-74848HIGH7
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesAug 27, 2026
CVE-2026-63041MEDIUM5.3
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesAug 26, 2026
CVE-2026-49872MEDIUM5.3
  • Apache APISIX logoApache APISIX
  • cpe:2.3:a:apache:apisix
NoYesJun 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management