CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94250
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX.An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache API
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog