BIT-apisix-2026-48895

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/apisix/BIT-apisix-2026-48895.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-apisix-2026-48895
Aliases
  • CVE-2026-48895
Published
2026-06-23T14:37:48.141Z
Modified
2026-06-23T15:15:06.676972239Z
Summary
Apache APISIX: Cas-auth Host header influence on CAS service URL
Details

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.

The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token.

This issue affects Apache APISIX: from 3.0.0 through 3.16.0.

Users are recommended to upgrade to version 3.17.0, which fixes the issue.

Database specific
{
    "severity": "Low",
    "cpes": [
        "cpe:2.3:a:apache:apisix:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / apisix

Package

Name
apisix
Purl
pkg:bitnami/apisix

Severity

  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.17.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/apisix/BIT-apisix-2026-48895.json"