Impact
This vulnerability in Apache APISIX’s attach-consumer-label plugin allows an attacker to send client‑supplied consumer‑label headers that are not sanitized. The flaw can be leveraged to elevate privileges or bypass authorization controls by manipulating these headers. The weakness is a classic example of trusting untrusted input, identified as CWE‑807.
Affected Systems
Affected installations run Apache APISIX versions 3.11.0 through 3.17.0. Users of these releases are susceptible, while later versions such as 3.18.0 contain the fix. The issue targets the attach-consumer-label plugin, which may be deployed in any APISIX‑based API gateway configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that while exploitation is possible, it may not be actively leveraged at scale. The likely attack vector involves crafting malicious HTTP headers sent to the APISIX gateway; no special pre‑conditions beyond sending the header are described, implying that any externally reachable APISIX instance could be targeted.
OpenCVE Enrichment