All verified exploits

CVE-2026-31908 Forged Identity Header via forward-auth Plugin

Pentest high Apache APISIX Added cve-verified-cve-2026-31908

Detects Apache APISIX versions 2.12.0 through 3.15.0 where the forward-auth plugin leaves client-supplied values intact for any header in upstream_headers that is missing from the auth response. When a route is fronted by forward-auth with identity headers (X-User-ID, X-User-Email, X-User-Role, X-Forwarded-User), an unauthenticated attacker can spoof the user identity by attaching the header to their request — bypassing authentication on any upstream that trusts the gateway-provided identity. The fix in 3.16.0 unconditionally calls set_header() so a nil value clears any client-injected header.

Is your app exploitable through CVE-2026-31908?

Scan your domain free