{
  "from_raw": "Abhishek Choudhary <shreemaanabhishek@apache.org>",
  "from": "Abhishek Choudhary <sh...@apache.org>",
  "gravatar": "8e902c76c97de450e20f005d9a05b8b0",
  "to": "an...@apache.org,\n de...@apisix.apache.org",
  "subject": "CVE-2026-94276: Apache APISIX: Openid-connect introspection validation issue",
  "message-id": "<d819b3bf-d424-1506-adf4-87abab855a2e@apache.org>",
  "mid": "txn3br25kl657fh15rwcy1oht1xbpyyk",
  "permalinks": [
    "txn3br25kl657fh15rwcy1oht1xbpyyk",
    "r5e92f3d62d660043402da0cc2436009730be59a56a1bd02afda8f43d@<dev.apisix.apache.org>"
  ],
  "dbid": "0263f4b423fe1cd42281c457de5970e6508230211946ffaf2238920f512b310c",
  "cc": "",
  "epoch": 1790845411,
  "list": "<dev.apisix.apache.org>",
  "list_raw": "<dev.apisix.apache.org>",
  "date": "2026/10/01 09:03:31",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n    CVSS 4.0: 5.1 (medium) CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N\n\nAffected versions:\n\n- Apache APISIX 3.12.0 through 3.18.0\n\nDescription:\n\nImproper Authentication vulnerability in Apache APISIX.\n\nOn a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get\u00a0accepted on a route restricted to another.\u00a0This issue affects Apache APISIX: from 3.12.0 through 3.18.0.\n\nUsers are recommended to upgrade to version 3.19.0, which fixes the issue.\n\nCredit:\n\nsec-reex (reporter)\nshreemaan-abhishek (coordinator)\nshreemaan-abhishek (remediation developer)\n\nReferences:\n\nhttps://apisix.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-94276\n\n",
  "body_short": "Severity: \n    CVSS 4.0: 5.1 (medium) CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N\n\nAffected versions:\n\n- Apache APISIX 3.12.0 through 3.18.0\n\nDescription:\n\nImproper Authentication v",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@apisix.apache.org",
  "size": 3901,
  "id": "txn3br25kl657fh15rwcy1oht1xbpyyk"
}