help request: Will APISIX be affected by the vulnerability CVE-2026-49975?
- Dominant language
- Lua
- Stars
- 17.1k
- Forks
- 2.9k
- Avg merge
- 3d 16h
- Merged PRs (30d)
- 63
Description
### Description
APISIX is developed based on Nginx. Nginx versions < 1.29.8 are affected by this vulnerability. Then, does the APISIX version need to be upgraded?
### Environment
- APISIX version (run `apisix version`):
- Operating system (run `uname -a`):
- OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
- etcd version, if relevant (run `curl http://127.0.0.1:9090/v1/server_info`):
- APISIX Dashboard version, if relevant:
- Plugin runner version, for issues related to plugin runners:
- LuaRocks version, for installation issues (run `luarocks --version`):
Contributor guide
Research direction
Start by collecting the environment details requested in the issue, especially the outputs of `apisix version`, `openresty -V` or `nginx -V`, and the relevant APISIX version. Compare the bundled Nginx/OpenResty version with the CVE's affected range and verify whether APISIX publishes a corresponding upgrade or advisory. Done means documenting a supported conclusion about exposure and required upgrade path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- nginx
- Domain
- backend-api-design, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100