{
  "from_raw": "Abhishek Choudhary <shreemaanabhishek@apache.org>",
  "from": "Abhishek Choudhary <sh...@apache.org>",
  "gravatar": "8e902c76c97de450e20f005d9a05b8b0",
  "to": "an...@apache.org,\n de...@apisix.apache.org",
  "subject": "CVE-2026-94212: Apache APISIX: unauthenticated impersonation issue in saml-auth",
  "message-id": "<25631c2d-bbec-470a-0e5a-ccfa792d5242@apache.org>",
  "mid": "1230fnojnmc7bfz3n0nkt7tkcld9d1sc",
  "permalinks": [
    "1230fnojnmc7bfz3n0nkt7tkcld9d1sc",
    "rededb99b269eeb51222e525e0ecccefa3861b459ca04642301dbb564@<dev.apisix.apache.org>"
  ],
  "dbid": "e073ebda78f96750633a553a897303fb15d2b45432c19250d39554dfe3e877ea",
  "cc": "",
  "epoch": 1790845002,
  "list": "<dev.apisix.apache.org>",
  "list_raw": "<dev.apisix.apache.org>",
  "date": "2026/10/01 08:56:42",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n    CVSS 4.0: 6.4 (medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N\n\nAffected versions:\n\n- Apache APISIX 3.17.0 through 3.18.0\n\nDescription:\n\nImproper verification of cryptographic signature vulnerability in Apache APISIX.\n\n\n\nAny unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration.\u00a0This issue affects Apache APISIX: from 3.17.0 through 3.18.0.\n\n\n\nUsers are recommended to upgrade to version 3.19.0, which fixes the issue.\n\nCredit:\n\nLucasFutures (reporter)\nshreemaan-abhishek (coordinator)\nshreemaan-abhishek (remediation developer)\n\nReferences:\n\nhttps://apisix.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-94212\n\n",
  "body_short": "Severity: \n    CVSS 4.0: 6.4 (medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N\n\nAffected versions:\n\n- Apache APISIX 3.17.0 through 3.18.0\n\nDescription:\n\nImproper verification of ",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@apisix.apache.org",
  "size": 3927,
  "id": "1230fnojnmc7bfz3n0nkt7tkcld9d1sc"
}