Severity: Affected versions:
- Apache APISIX 3.11.0 through 3.17.0 Description: Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly. This issue affects Apache APISIX: from 3.11.0 through 3.17.0. Users are recommended to upgrade to version <pending>, which fixes the issue. Credit: tonghuaroot (reporter) References: https://apisix.apache.org https://www.cve.org/CVERecord?id=CVE-2026-63041
