Detects Apache APISIX versions 2.12.0 through 3.15.0 where the forward-auth plugin leaves client-supplied values intact for any header in upstream_headers that is missing from the auth response. When a route is fronted by forward-auth with identity headers (X-User-ID, X-User-Email, X-User-Role, X-Forwarded-User), an unauthenticated attacker can spoof the user identity by attaching the header to their request — bypassing authentication on any upstream that trusts the gateway-provided identity. The fix in 3.16.0 unconditionally calls set_header() so a nil value clears any client-injected header.
Is your app exploitable through CVE-2026-31908?
Scan your domain free