Description
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.



An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.



Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Published: 2026-10-01
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: Account takeover via session fixation
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a session fixation flaw (CWE‑352) in the feishu‑auth and dingtalk‑auth plugins of Apache APISIX. An attacker can force a user’s browser to start a session that the attacker controls by clicking a crafted link. Once the victim’s session is hijacked, the attacker can perform any action the user is authorized to carry out, such as uploading files, submitting forms, or binding accounts, all of which are recorded under the attacker’s account.

Affected Systems

Apache APISIX versions 3.17.0 through 3.18.0 contain the vulnerable plugins. All deployments of those versions that enable feishu‑auth or dingtalk‑auth are affected.

Risk and Exploitability

The CVSS score of 2.1 indicates low severity, yet the real impact is serious because the attacker gains the victim’s privileges. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. The attack vector requires only a user to click a malicious link, so prevention relies on patching or disabling the plugins, rather than on user education alone.

Generated by OpenCVE AI on October 1, 2026 at 13:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache APISIX to version 3.19.0 or later, which contains the fixed feishu‑auth and dingtalk‑auth plugins.
  • If an upgrade is not immediately possible, temporarily disable the feishu‑auth and dingtalk‑auth plugins until the next maintenance window.
  • Implement or enforce CSRF protection across the API gateway, such as rotating session cookies or adding SameSite attributes, to reduce the risk of session fixation attacks.

Generated by OpenCVE AI on October 1, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apisix
Vendors & Products Apache
Apache apisix

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Title Apache APISIX: session fixation issue in feishu-auth and dingtalk-auth plugin
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:51:30.180Z

Reserved: 2026-09-21T06:14:23.736Z

Link: CVE-2026-94220

cve-icon Vulnrichment

Updated: 2026-10-01T13:11:00.641Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T12:17:16.930

Modified: 2026-10-01T15:17:36.123

Link: CVE-2026-94220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:00:10Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)