CVE-2026-39999
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.
Ver en NVDAnálisis
Apache APISIX versions 2.2 to 3.16.0 contain a critical vulnerability in the jwt-auth plugin that allows attackers to completely bypass authentication. This allows unauthorized access to all services behind the gateway. Users are urged to upgrade to version 3.17.0 immediately.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCWE-290EPSS
Afecta
apache:apisixDescripción técnica
Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended to upgrade to version v3.17.0, which fixes the issue.