CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94220

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any wo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-94220 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-94220

UNKNOWNCVSS 0NVD feed

Published 1 October 2026 · tracked since 2 October 2026

Description

Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any wo

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]