Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-32638


Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.


Published

2024-05-02T10:15:08.443

Last Modified

2025-07-10T16:00:20.313

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-444
  • Type: Secondary
    CWE-444

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache apisix 3.8.0 Yes
Application apache apisix 3.9.0 Yes

References