SEPTEMBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-74848

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

Apache APISIX versions 2.12.0 through 3.17.0 are vulnerable to HTTP request/response smuggling, allowing attackers to manipulate responses sent to clients, potentially exposing sensitive data or causing unauthorized actions. Organizations using affected versions should prioritize upgrading to version 3.18.0 to mitigate this high-severity risk.

CVE
CVE-2026-74848
Severity
HIGH
CVSS
7.5
EPSS
0.48%
Apache

Original NVD Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes. This issue affects Apache APISIX: from 2.12.0 through 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)