THREATOPS
THREAT OPSThreat News › CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins

CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins

medoss_secPublished 2026-08-26

<p>Posted by Abhishek Choudhary on Aug 26</p>Severity: <br /> <br /> Affected versions:<br /> <br /> - Apache APISIX 2.12.0 through 3.17.0<br /> <br /> Description:<br /> <br /> Inconsistent Interpretation of HTTP Requests (&apos;HTTP Request/Response Smuggling&apos;) vulnerability in Apache APISIX.<br /> <br /> An attacker could make other clients receive attacker-chosen or other users&apos; resp

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/590