Impact
The vulnerability in Apache APISIX stems from inconsistent interpretation of HTTP requests, enabling HTTP Request/Response smuggling. An attacker can manipulate the serverless‑plugin routes to deliver attacker‑chosen or other users’ responses to otherwise unrelated clients, resulting in unauthorized disclosure or alteration of data visible to the victims.
Affected Systems
Apache APISIX versions 2.12.0 through 3.17.0 are affected. The issue exists across all releases in this range, regardless of deployment model. The vendor recommends migrating to version 3.18.0 to eliminate the flaw.
Risk and Exploitability
With a CVSS score of 7, the flaw is classified as high severity. Although EPSS data is not available and it is not listed in CISA’s KEV catalog, the attack vector is likely network‑based, requiring the attacker to craft a malicious request to the serverless‑plugin endpoint. Successful exploitation causes the victim client to receive a forged response, leading to data exposure or transaction manipulation. This represents a serious risk to confidentiality and integrity.
OpenCVE Enrichment