THREAT OPS › Threat News › CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 2.12.0 through 3.17.0<br /> <br /> Description:<br /> <br /> Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX.<br /> <br /> An attacker could make other clients receive attacker-chosen or other users' resp
MITRE ATT&CK techniques
- ServerlessT1583.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- CVE-2026-74848cve
Original source: https://seclists.org/oss-sec/2026/q3/590