apache / apache/apisix

help request: Will APISIX be affected by the vulnerability CVE-2026-42533?

Open
#13,734 2 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
Lua
Stars
17.1k
Forks
2.9k
Avg merge
3d 16h
Merged PRs (30d)
63

Description

### Description

APISIX is built upon Nginx, and most versions of Nginx are affected by this vulnerability. So, does APISIX need to be upgraded?

### Environment

- APISIX version (run `apisix version`): 3.2.0、3.13.0
- Operating system (run `uname -a`):
- OpenResty / Nginx version (run `openresty -V` or `nginx -V`):
- etcd version, if relevant (run `curl http://127.0.0.1:9090/v1/server_info`):
- APISIX Dashboard version, if relevant:
- Plugin runner version, for issues related to plugin runners:
- LuaRocks version, for installation issues (run `luarocks --version`):

Contributor guide

Open the contributing guide

Research direction

Start by reviewing CVE-2026-42533 and comparing its affected Nginx versions with the Nginx or OpenResty version reported by `nginx -V` or `openresty -V`. Check the APISIX 3.2.0 and 3.13.0 environments, then document whether APISIX is affected and whether an upgrade is required.

Written by the indexing model from the issue text.

Assessment

Tech stack
nginx
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.