THREAT OPS › Threat News › CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
<p>Posted by Abhishek Choudhary on Aug 25</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 3.11.0 through 3.17.0<br /> <br /> Description:<br /> <br /> Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.<br /> <br /> This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain <br /> valu
Indicators of compromise
- CVE-2026-63041cve
Original source: https://seclists.org/oss-sec/2026/q3/589