ID

VAR-202604-1847


CVE

CVE-2026-31924


TITLE

Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613

DESCRIPTION

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plaintext HTTP This issue affects Apache APISIX: from 2.99.0 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .There is a possibility that some of the information handled by the software may be leaked to the outside. However, the information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks that exploit this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2026-31924 // JVNDB: JVNDB-2026-011613

AFFECTED PRODUCTS

vendor:apachemodel:apisixscope:ltversion:3.16.0

Trust: 1.0

vendor:apachemodel:apisixscope:gteversion:2.99.0

Trust: 1.0

vendor:apachemodel:apisixscope:eqversion:2.99.0 that's all 3.16.0

Trust: 0.8

vendor:apachemodel:apisixscope: - version: -

Trust: 0.8

vendor:apachemodel:apisixscope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613 // NVD: CVE-2026-31924

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-31924
value: MEDIUM

Trust: 1.0

OTHER: JVNDB-2026-011613
value: MEDIUM

Trust: 0.8

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-31924
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-011613
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613 // NVD: CVE-2026-31924

PROBLEMTYPE DATA

problemtype:CWE-319

Trust: 1.0

problemtype:Sending important information in clear text (CWE-319) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613 // NVD: CVE-2026-31924

PATCH

title:Apache APISIXurl:https://lists.apache.org/thread/sqxjjlt87c1q28db28ztdxylm5pgwohq

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613

EXTERNAL IDS

db:NVDid:CVE-2026-31924

Trust: 2.6

db:OPENWALLid:OSS-SECURITY/2026/04/14/2

Trust: 1.0

db:JVNDBid:JVNDB-2026-011613

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613 // NVD: CVE-2026-31924

REFERENCES

url:https://lists.apache.org/thread/sqxjjlt87c1q28db28ztdxylm5pgwohq

Trust: 1.0

url:http://www.openwall.com/lists/oss-security/2026/04/14/2

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-31924

Trust: 0.8

sources: JVNDB: JVNDB-2026-011613 // NVD: CVE-2026-31924

SOURCES

db:JVNDBid:JVNDB-2026-011613
db:NVDid:CVE-2026-31924

LAST UPDATE DATE

2026-06-19T22:41:03.828000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-011613date:2026-04-20T01:52:00
db:NVDid:CVE-2026-31924date:2026-04-17T18:38:47.130

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-011613date:2026-04-20T00:00:00
db:NVDid:CVE-2026-31924date:2026-04-14T09:16:35.953