LOW 2.1 NVD
CVE-2026-94220
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.
An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.
Users are recommended to upgrade to version 3.19.0, which fixes the issue.
References
- https://lists.apache.org/thread.html/bf5q45ddyr2hf3hxkt56dzjlttgpdg78
- http://www.openwall.com/lists/oss-security/2026/10/01/5
- https://www.openwall.com/lists/oss-security/2026/10/01/5
This low severity vulnerability with a CVSS score of 2.1 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.