THREAT OPS › Threat News › CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 3.17.0<br /> <br /> Description:<br /> <br /> Inefficient Algorithmic Complexity vulnerability in Apache APISIX.<br /> <br /> A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.<br /> <br /> This issue affects Apache API
Indicators of compromise
- CVE-2026-75005cve
- https://apisix.apache.orgurl
Original source: https://seclists.org/oss-sec/2026/q3/591