{
  "from_raw": "Abhishek Choudhary <shreemaanabhishek@apache.org>",
  "from": "Abhishek Choudhary <sh...@apache.org>",
  "gravatar": "8e902c76c97de450e20f005d9a05b8b0",
  "to": "an...@apache.org,\n de...@apisix.apache.org",
  "subject": "CVE-2026-82806: Apache APISIX: cross-request permission pollution via static permission list mutation",
  "message-id": "<0ebf94c9-1b46-20cc-d373-25a08a8390c7@apache.org>",
  "mid": "wvkv2b4oy2fh9v79d30gtsy0bhqmzcdd",
  "permalinks": [
    "wvkv2b4oy2fh9v79d30gtsy0bhqmzcdd",
    "r97e5ba30ca47becff4e72cbd689eb89d9bc990a48de51b87f62eb929@<dev.apisix.apache.org>"
  ],
  "dbid": "18a1784818ffc7b23fc4642adc60b4f6b21b03521f057933867a7217c61ec10b",
  "cc": "",
  "epoch": 1790844930,
  "list": "<dev.apisix.apache.org>",
  "list_raw": "<dev.apisix.apache.org>",
  "date": "2026/10/01 08:55:30",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: \n    CVSS 4.0: 5.3 (medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N\n\nAffected versions:\n\n- Apache APISIX 2.3.0 before 3.7.0\n\nDescription:\n\nExposure of data element to wrong session vulnerability in Apache APISIX.\n\n\n\nThis issue affects Apache APISIX: from 2.3.0 before 3.7.0.\n\n\n\nUnder a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and inconsistent access-control decisions.\n\n\n\nUsers are recommended to upgrade to version 3.7.0 or higher, which fixes the issue.\n\nCredit:\n\nLok (reporter)\n\nReferences:\n\nhttps://apisix.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-82806\n\n",
  "body_short": "Severity: \n    CVSS 4.0: 5.3 (medium) CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N\n\nAffected versions:\n\n- Apache APISIX 2.3.0 before 3.7.0\n\nDescription:\n\nExposure of data element to ",
  "html_source_only": false,
  "attachments": [],
  "forum": "dev@apisix.apache.org",
  "size": 3937,
  "id": "wvkv2b4oy2fh9v79d30gtsy0bhqmzcdd"
}