Impact
The batch‑requests plugin in Apache APISIX performs unbounded allocation of resources when aggregating responses for batch requests. An unauthenticated caller can repeatedly invoke the publicly exposed batch endpoint, causing the gateway worker process to run out of memory and terminate. This leads to a loss of service for all traffic handled by that worker and potentially for the entire API gateway, compromising availability.
Affected Systems
Apache Software Foundation’s Apache APISIX is affected from version 1.3.0 through 3.18.0. Versions prior to 1.3.0 or later than 3.18.0 are not known to be vulnerable, and upgrading to 3.19.0 resolves the issue.
Risk and Exploitability
The CVSS score of 8.2 highlights a high severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely with no authentication required by sending crafted batch requests over the network; the lack of throttling or resource limits makes it easy to trigger OOM. Because the impact is a denial of service affecting the availability of the gateway, the risk is considerable.
OpenCVE Enrichment