ID

VAR-202604-1987


CVE

CVE-2026-31923


TITLE

Apache Software Foundation of APISIX Vulnerability in plaintext transmission of important information in

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614

DESCRIPTION

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, which fixes the issue. 3.16.0 It is recommended to upgrade to .All information handled by the software may be leaked to the outside. In addition, information handled by the software will not be rewritten. Furthermore, the software will not stop. Furthermore, attacks exploiting this vulnerability will not affect other software

Trust: 1.62

sources: NVD: CVE-2026-31923 // JVNDB: JVNDB-2026-011614

AFFECTED PRODUCTS

vendor:apachemodel:apisixscope:ltversion:3.16.0

Trust: 1.0

vendor:apachemodel:apisixscope:gteversion:0.7

Trust: 1.0

vendor:apachemodel:apisixscope:eqversion:0.7 that's all 3.16.0

Trust: 0.8

vendor:apachemodel:apisixscope:eqversion: -

Trust: 0.8

vendor:apachemodel:apisixscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614 // NVD: CVE-2026-31923

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-31923
value: HIGH

Trust: 1.0

OTHER: JVNDB-2026-011614
value: HIGH

Trust: 0.8

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2026-31923
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-011614
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614 // NVD: CVE-2026-31923

PROBLEMTYPE DATA

problemtype:CWE-319

Trust: 1.0

problemtype:Sending important information in clear text (CWE-319) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614 // NVD: CVE-2026-31923

PATCH

title:Apache APISIXurl:https://lists.apache.org/thread/0pjs72l7qj83j3srw1l1toyj24bsgkds

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614

EXTERNAL IDS

db:NVDid:CVE-2026-31923

Trust: 2.6

db:OPENWALLid:OSS-SECURITY/2026/04/14/1

Trust: 1.0

db:JVNDBid:JVNDB-2026-011614

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614 // NVD: CVE-2026-31923

REFERENCES

url:https://lists.apache.org/thread/0pjs72l7qj83j3srw1l1toyj24bsgkds

Trust: 1.0

url:http://www.openwall.com/lists/oss-security/2026/04/14/1

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-31923

Trust: 0.8

sources: JVNDB: JVNDB-2026-011614 // NVD: CVE-2026-31923

SOURCES

db:JVNDBid:JVNDB-2026-011614
db:NVDid:CVE-2026-31923

LAST UPDATE DATE

2026-06-19T22:32:57.655000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-011614date:2026-04-20T01:52:00
db:NVDid:CVE-2026-31923date:2026-04-17T18:39:45.377

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-011614date:2026-04-20T00:00:00
db:NVDid:CVE-2026-31923date:2026-04-14T09:16:35.817