Vulnerability Details CVE-2026-63041
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.
This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.
This issue affects Apache APISIX: from 3.11.0 through 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 38.0%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-63041
-
cpe:2.3:a:apache:apisix:3.11.0
-
cpe:2.3:a:apache:apisix:3.12.0
-
cpe:2.3:a:apache:apisix:3.13.0
-
cpe:2.3:a:apache:apisix:3.14.0
-
cpe:2.3:a:apache:apisix:3.14.1
-
cpe:2.3:a:apache:apisix:3.15.0
-
cpe:2.3:a:apache:apisix:3.16.0
-
cpe:2.3:a:apache:apisix:3.17.0