CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94220
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any wo
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog