CVE-2026-31908
Apache APISIX: forward auth plugin allows header injection
- Published
- Apr 14, 2026
- Updated
- Apr 16, 2026
- Assigning CNA
- apache
- Evidence observed
- Aug 25, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NLow · next 30 days
- Percentile
- 43.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers. This issue affects Apache APISIX: from 2.12.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue.
Sources
1Proof-of-concept exploit for CVE-2026-31908, a critical header injection vulnerability in Apache APISIX, demonstrating authentication bypass and privilege escalation through CRLF injection in the forward-auth plugin.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.