Description
Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX.



An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0.



Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Published: 2026-10-01
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service via worker memory exhaustion
Action: Patch
AI Analysis

Impact

The batch‑requests plugin in Apache APISIX performs unbounded allocation of resources when aggregating responses for batch requests. An unauthenticated caller can repeatedly invoke the publicly exposed batch endpoint, causing the gateway worker process to run out of memory and terminate. This leads to a loss of service for all traffic handled by that worker and potentially for the entire API gateway, compromising availability.

Affected Systems

Apache Software Foundation’s Apache APISIX is affected from version 1.3.0 through 3.18.0. Versions prior to 1.3.0 or later than 3.18.0 are not known to be vulnerable, and upgrading to 3.19.0 resolves the issue.

Risk and Exploitability

The CVSS score of 8.2 highlights a high severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely with no authentication required by sending crafted batch requests over the network; the lack of throttling or resource limits makes it easy to trigger OOM. Because the impact is a denial of service affecting the availability of the gateway, the risk is considerable.

Generated by OpenCVE AI on October 1, 2026 at 13:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache APISIX to version 3.19.0 or later, which removes the unbounded batch allocation bug.
  • If upgrading is delayed, immediately restrict or disable the batch endpoint to prevent malformed requests from reaching the worker.
  • Apply network‑level rate limiting or traffic shaping on the batch route to reduce the rate of incoming requests and mitigate the risk of exhausting worker memory.

Generated by OpenCVE AI on October 1, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 01 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache Software Foundation
Apache Software Foundation apache Apisix
Vendors & Products Apache Software Foundation
Apache Software Foundation apache Apisix

Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
Title Apache APISIX: Batch response aggregation can exhaust worker memory
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Apache Software Foundation Apache Apisix
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-01T14:51:08.084Z

Reserved: 2026-09-21T08:46:09.162Z

Link: CVE-2026-94250

cve-icon Vulnrichment

Updated: 2026-10-01T13:11:01.606Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T12:17:17.063

Modified: 2026-10-01T15:17:36.277

Link: CVE-2026-94250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:00:10Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling