Impact
Apache APISIX suffers from an inefficient algorithmic complexity flaw that allows a single small request to lock a gateway worker at 100 percent CPU usage for an extended period. Because the worker remains busy, normal traffic cannot be processed, effectively shutting down the service. The flaw is classified as CWE-407 and results in a denial of service with no direct impact on confidentiality or integrity.
Affected Systems
The affected product is Apache Software Foundation’s Apache APISIX, specifically version 3.17.0. Users are advised to upgrade to version 3.18.0, which contains the fix.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; an adversary can send a crafted request to the gateway to trigger the compute‑heavy loop and exhaust CPU resources. Given the severity and lack of mitigation controls, the risk of exploitation is significant for exposed instances.
OpenCVE Enrichment