Impact
This vulnerability arises from the use of non‑canonical URL paths for authorization in Apache APISIX. An attacker can craft an encoded path that bypasses the intended route‑based policy and reaches an upstream endpoint that should be protected, thereby receiving unauthorized access to that resource.
Affected Systems
Apache APISIX from version 2.14.1 through 3.18.0 is affected. The software is distributed by the Apache Software Foundation and the issue applies to all deployments of these versions regardless of platform.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalogue, so the current exploitation probability is unknown. The attack vector requires crafting a request with a non‑canonical or encoded path that takes advantage of a permissive route overlapping a protected one. Once this path is used, the request is served by the protected upstream endpoint without the intended authentication checks, enabling unauthorized access. Although no public exploit has been reported, the flaw remains exploitable by attackers with knowledge of Apache APISIX routing and URL canonicalization.
OpenCVE Enrichment