Description
Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a malformed Cookie header to skip rate limit checks and exceed thresholds intended to restrict costly model backend calls.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Rate Limit Bypass
Action: Patch ASAP
AI Analysis

Impact

Higress before version 2.2.4 crashes when processing a Cookie header segment that contains no equals sign, and the accompanying plugin wrapper recovers and issues a continue action. That action bypasses the AI token rate limiting that is intended to constrain expensive model backend calls, allowing an unauthenticated attacker to send a crafted HTTP request and avoid all rate‑limit checks. The result is uncontrolled access to costly backend services, which can lead to denial of service or significant cost escalation.

Affected Systems

The vulnerability affects the higress‑group/higress product for all releases prior to and including 2.2.3. The ai‑token‑ratelimit plugin must be upgraded to version 2.2.4 or later to incorporate the patch that protects against malformed Cookie headers.

Risk and Exploitability

The CVSS score of 6.9 reflects moderate severity, while the EPSS score below 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an unauthenticated HTTP client to send a request containing a Cookie header without an equals sign to the Higress gateway; no privileges or additional conditions are needed beyond network connectivity.

Generated by OpenCVE AI on September 17, 2026 at 22:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade higress to version 2.2.4 or later to apply the official fix.
  • Update the ai‑token‑ratelimit plugin to the patched version included in the 2.2.4 release.
  • Configure request processing to reject or strip Cookie header segments that lack an equals sign, preventing the rate‑limit bypass path.
  • If the patch cannot be applied immediately, increase AI token rate‑limit thresholds temporarily to reduce the impact of potential service abuse until the update is deployed.

Generated by OpenCVE AI on September 17, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Higress-group
Higress-group higress
Vendors & Products Higress-group
Higress-group higress

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a malformed Cookie header to skip rate limit checks and exceed thresholds intended to restrict costly model backend calls.
Title Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header
Weaknesses CWE-703
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Higress-group Higress
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:04:18.836Z

Reserved: 2026-09-16T19:31:53.563Z

Link: CVE-2026-92790

cve-icon Vulnrichment

Updated: 2026-09-17T15:04:15.719Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:28.480

Modified: 2026-09-24T20:48:01.433

Link: CVE-2026-92790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:11Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions