Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0.
Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache apisix |
|
CPEs | cpe:2.3:a:apache:apisix:3.8.0:*:*:*:*:*:*:* cpe:2.3:a:apache:apisix:3.9.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Apache
Apache apisix |
Thu, 13 Feb 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue. | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue. |

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T17:52:13.382Z
Reserved: 2024-04-16T11:56:04.600Z
Link: CVE-2024-32638

Updated: 2024-08-02T02:13:40.364Z

Status : Analyzed
Published: 2024-05-02T10:15:08.443
Modified: 2025-07-10T16:00:20.313
Link: CVE-2024-32638

No data.

No data.