AUGUST 29, 2026
Live Feed
Back to database
Case File

CVE-2026-75005

HIGH · CVSS 7.5 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Apache APISIX versions prior to 3.18.0 are vulnerable to an inefficient algorithmic complexity issue that can cause a single small request to monopolize a gateway worker's CPU resources, leading to potential denial-of-service conditions. This high-severity vulnerability should be prioritized by organizations using affected versions of Apache APISIX to ensure service availability and performance. Users are advised to upgrade to version 3.18.0 to mitigate this risk.

CVE
CVE-2026-75005
Severity
HIGH
CVSS
7.5
EPSS
0.48%
Apache

Original NVD Description

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes. This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)