PoC Archive PoC Archive

tag

Apache-Apisix

  • CVE-2026-49230 web CRITICAL 9.1

    Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)

    The jwe-decrypt plugin is an auth-type APISIX plugin that decrypts an incoming JWE token with a per-consumer AES-256-GCM secret and forwards the plaintext upstream as proof of authentication. Its internal helper jwedecryptwithobj() returns only the decrypted…

    Patched 2026-07-27