Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX.

An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes.




This issue affects Apache APISIX: from 2.12.0 through 3.17.0.



Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Published: 2026-08-27
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Apache APISIX stems from inconsistent interpretation of HTTP requests, enabling HTTP Request/Response smuggling. An attacker can manipulate the serverless‑plugin routes to deliver attacker‑chosen or other users’ responses to otherwise unrelated clients, resulting in unauthorized disclosure or alteration of data visible to the victims.

Affected Systems

Apache APISIX versions 2.12.0 through 3.17.0 are affected. The issue exists across all releases in this range, regardless of deployment model. The vendor recommends migrating to version 3.18.0 to eliminate the flaw.

Risk and Exploitability

With a CVSS score of 7, the flaw is classified as high severity. Although EPSS data is not available and it is not listed in CISA’s KEV catalog, the attack vector is likely network‑based, requiring the attacker to craft a malicious request to the serverless‑plugin endpoint. Successful exploitation causes the victim client to receive a forged response, leading to data exposure or transaction manipulation. This represents a serious risk to confidentiality and integrity.

Generated by OpenCVE AI on August 27, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache APISIX 3.18.0 or later to apply the official fix.
  • Disable or remove any unneeded serverless‑plugin functionality that could expose smuggling pathways until patched.
  • Conduct functional tests on the serverless‑plugin routes to confirm that responses are strictly those expected by the client.
  • Implement logging and monitoring of HTTP response patterns to alert on anomalous or forged responses.

Generated by OpenCVE AI on August 27, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apisix
Vendors & Products Apache
Apache apisix

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Title Apache APISIX: Cross-user response poisoning in serverless plugins
Weaknesses CWE-444
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-27T12:05:30.790Z

Reserved: 2026-08-17T08:09:53.876Z

Link: CVE-2026-74848

cve-icon Vulnrichment

Updated: 2026-08-27T10:22:00.110Z

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:36.337

Modified: 2026-08-27T13:18:36.983

Link: CVE-2026-74848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T11:00:06Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')