{
  "from_raw": "Abhishek Choudhary <shreemaanabhishek@apache.org>",
  "from": "Abhishek Choudhary <sh...@apache.org>",
  "gravatar": "8e902c76c97de450e20f005d9a05b8b0",
  "to": "an...@apache.org,\n de...@apisix.apache.org",
  "subject": "CVE-2026-94250: Apache APISIX: Batch response aggregation can exhaust worker memory",
  "message-id": "<b41c3f05-ba25-592b-c0ca-6558a8894894@apache.org>",
  "mid": "l7o9w8pw3w3f12vf9ybm7xtfzoo6qct4",
  "permalinks": [
    "l7o9w8pw3w3f12vf9ybm7xtfzoo6qct4",
    "r4658c2aa136c7c19140d9623e2defcb836daa6c2b10e7828b12cc10a@<dev.apisix.apache.org>"
  ],
  "dbid": "acc9399073240e37c68dc8ca9dc584c2a591d4df66d0e98d1dd21db03d2fbb3b",
  "cc": "",
  "epoch": 1790845216,
  "list": "<dev.apisix.apache.org>",
  "list_raw": "<dev.apisix.apache.org>",
  "date": "2026/10/01 09:00:16",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n    CVSS 4.0: 8.2 (high) CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\n\nAffected versions:\n\n- Apache APISIX 1.3.0 through 3.18.0\n\nDescription:\n\nAllocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX.\n\n\n\nAn unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the\u00a0batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0.\n\n\n\nUsers are recommended to upgrade to version 3.19.0, which fixes the issue.\n\nCredit:\n\nZiyue (reporter)\nshreemaan-abhishek (remediation developer)\nshreemaan-abhishek (coordinator)\n\nReferences:\n\nhttps://apisix.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-94250\n\n",
  "body_short": "Severity: \n    CVSS 4.0: 8.2 (high) CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N\n\nAffected versions:\n\n- Apache APISIX 1.3.0 through 3.18.0\n\nDescription:\n\nAllocation of resources with",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@apisix.apache.org",
  "size": 3969,
  "id": "l7o9w8pw3w3f12vf9ybm7xtfzoo6qct4"
}