CVE-2025-46647

Source
https://cve.org/CVERecord?id=CVE-2025-46647
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46647.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46647
Aliases
Published
2025-07-02T12:15:28.227Z
Modified
2026-04-10T05:28:28.901401Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability of plugin openid-connect in Apache APISIX.

This vulnerability will only have an impact if all of the following conditions are met: 1. Use the openid-connect plugin with introspection mode 2. The auth service connected to openid-connect provides services to multiple issuers 3. Multiple issuers share the same private key and relies only on the issuer being different

If affected by this vulnerability, it would allow an attacker with a valid account on one of the issuers to log into the other issuer.

This issue affects Apache APISIX: until 3.12.0.

Users are recommended to upgrade to version 3.12.0 or higher.

References

Affected packages

Git / github.com/apache/apisix

Affected ranges

Type
GIT
Repo
https://github.com/apache/apisix
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.12.0"
        }
    ]
}

Affected versions

0.*
0.9-RC1
3.*
3.2.0
3.6.0
3.7.0
3.8.0
3.9.0
v0.*
v0.2
v0.3
v0.3-1
v0.4
v0.4.1
v0.5
v0.7
v0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46647.json"