CVE-2026-94269

CVE-2026-94269 published: Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies w...

View full NVD advisory → ← Back to CVE watch