CVE-2022-24112
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
- Published
- Feb 11, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- apache
- Evidence observed
- Mar 16, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
Sources
12Proof-of-Concept exploit for Apache APISIX 2.12.x RCE (CVE-2022-24112) via Lua filter_func injection. Executes arbitrary system commands on vulnerable targets.
- CVE-2022-24112Exploit
CVE-2022-24112:Apache APISIX apisix/batch-requests RCE
- cve-2022-24112Exploit
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.