tag
Apache-Apisix
CVE-2026-49230
web
CRITICAL 9.1
Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
The jwe-decrypt plugin is an auth-type APISIX plugin that decrypts an incoming JWE token with a per-consumer AES-256-GCM secret and forwards the plaintext upstream as proof of authentication. Its internal helper jwedecryptwithobj() returns only the decrypted…
Patched
2026-07-27