MEDIUM 5.7 NVD
CVE-2026-78242
Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the
Insertion of sensitive information into log file vulnerability in Apache APISIX.
This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure.
This issue affects Apache APISIX: 3.17.0.
Users are recommended to upgrade to version 3.18.0, which fixes the issue.
References
- https://lists.apache.org/thread.html/qxzsyw1pbgxg4sqkc4t2g8h4w2q0mvsn
- http://www.openwall.com/lists/oss-security/2026/10/01/2
- https://www.openwall.com/lists/oss-security/2026/10/01/2
This medium severity vulnerability with a CVSS score of 5.7 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.