THREATOPS
THREAT OPSThreat News › CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS

CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS

medoss_secPublished 2026-08-26

<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 3.17.0<br /> <br /> Description:<br /> <br /> Inefficient Algorithmic Complexity vulnerability in Apache APISIX.<br /> <br /> A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.<br /> <br /> This issue affects Apache API

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/591