Skip to content
Weekly Signal
Live intelligence Updated 19 Aug 2026 · 13:41 UTC

Apache · APISIX

CVE-2022-24112

Apache APISIX Authentication Bypass Vulnerability

Recommended action

Validate affected assets and exposure now, then remediate on an accelerated schedule. Apply updates per vendor instructions.

View response plan
CVSS9.8
EPSS96.0%
KEVYes
ExploitationConfirmed exploitation
PatchPatch or guidance available ↓

Assessment

Why it matters

CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 96.0%; technical severity is CVSS 9.8.

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

Who should care

  • Teams operating APISIX
  • Vulnerability and exposure management teams
  • Security operations teams monitoring exploitation activity

Response plan

What I would do

  1. Confirm whether APISIX is present in the environment.
  2. Identify affected versions and establish whether vulnerable services are exposed or reachable.
  3. Apply updates per vendor instructions.
  4. Review relevant security telemetry for evidence of attempted or successful exploitation.
  5. Document the remediation decision and track it to verified completion.

Vendor remediation

Patch and remediation links

Use the vendor source below to confirm the correct fixed version, package or mitigation for your affected product.

Technical details

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-290
Affected versions
Apache APISIX (Start Including: 2.11.0, End Excluding: 2.12.1)
Published
11 February 2022
Attack vector
Network
Privileges required
None
User interaction
None

Signal timeline

  1. CVE published
  2. Added to CISA KEV
  3. Latest EPSS score: 96.0%
  4. Signal calculated at 84

External references

Live public intelligence This assessment combines public-source evidence. Validate the affected product, version and exposure against your own environment before making a risk decision.