Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319

Apache APISIX: information disclosure

Medium5.7CVE-2026-78242 · Published Oct 1, 2026

Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure.  This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Affected versions

PackageAffectedFixed in
Apache APISIX
Product
<= 3.17.0No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-532

More Apache Software Foundation advisories

All Apache Software Foundation
Advisory
Apache HTTP Server: integer overflow
High8.8Oct 1
Apache HTTP Server: use after free
High7.3Oct 1
Path equivalence: '/./'
Medium5.3Oct 1
Apache HTTP Server: request smuggling
High7.5Oct 1
Apache HTTP Server: authentication bypass
High8.1Oct 1
Apache HTTP Server: exposed files
Medium5.3Oct 1