apache / apache/apisix

help request: Security advisory references 3.16.1 as fix version, but release is not available — requesting clarification on release timeline

Open
#13,589 0 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
Lua
Stars
17.1k
Forks
2.9k
Avg merge
3d 16h
Merged PRs (30d)
63

Description

### Description

### Problem Description

> https://mp.weixin.qq.com/s/zsv3QpTipcnjvpWK7kZ6sw

The Apache APISIX security advisory published on June 19, 2026 states that **3.16.1** is the fixed version for four CVEs (CVE-2026-39998, CVE-2026-39999, CVE-2026-44046, CVE-2026-44087), and explicitly recommends users who "cannot immediately upgrade to 3.17.0" to "at least upgrade to 3.16.1."

However, upon verification:
- [GitHub Releases](https://github.com/apache/apisix/releases) shows **3.16.0** as the latest version
- [Docker Hub](https://hub.docker.com/r/apache/apisix/tags) has no **3.16.1** tag
- Official download channels do not provide version **3.16.1**

### Requests

1. **What is the concrete release timeline for 3.16.1?** Is there a published date or ETA?
2. **Why was the advisory published before the release?** Is this expected process, or is there a release pipeline blockage?

### Environment

- APISIX version (run `apisix version`):
- Operating system (run `uname -a`):
- OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
- etcd version, if relevant (run `curl http://127.0.0.1:9090/v1/server_info`):
- APISIX Dashboard version, if relevant:
- Plugin runner version, for issues related to plugin runners:
- LuaRocks version, for installation issues (run `luarocks --version`):

Contributor guide

Open the contributing guide

Research direction

Start by comparing the June 19, 2026 security advisory with the GitHub Releases page, Docker Hub tags, and official download channels mentioned in the issue. Done means confirming the availability of 3.16.1 and providing a concrete release timeline or an explanation of the advisory and release process.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, nginx
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.