apache / apache/apisix

help request: Will APISIX be affected by the vulnerability CVE-2026-49975?

Open
#13,631 3 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
Lua
Stars
17.1k
Forks
2.9k
Avg merge
3d 16h
Merged PRs (30d)
63

Description

### Description

APISIX is developed based on Nginx. Nginx versions < 1.29.8 are affected by this vulnerability. Then, does the APISIX version need to be upgraded?

### Environment

- APISIX version (run `apisix version`):
- Operating system (run `uname -a`):
- OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
- etcd version, if relevant (run `curl http://127.0.0.1:9090/v1/server_info`):
- APISIX Dashboard version, if relevant:
- Plugin runner version, for issues related to plugin runners:
- LuaRocks version, for installation issues (run `luarocks --version`):

Contributor guide

Open the contributing guide

Research direction

Start by collecting the environment details requested in the issue, especially the outputs of `apisix version`, `openresty -V` or `nginx -V`, and the relevant APISIX version. Compare the bundled Nginx/OpenResty version with the CVE's affected range and verify whether APISIX publishes a corresponding upgrade or advisory. Done means documenting a supported conclusion about exposure and required upgrade path.

Written by the indexing model from the issue text.

Assessment

Tech stack
nginx
Domain
backend-api-design, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.