CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94269
UNKNOWNCVSS 0NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX.In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that sh
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog