PoC Archive PoC Archive

tag

Api-Gateway

Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
CVE-2026-49230 web Patched
CVE-2026-49230webCRITICAL 9.1Patched2026-07-27Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
CVE-2026-31908 web Patched
CVE-2026-31908webCRITICAL 10Patched2026-07-05Floci API Gateway VTL RCE + IAM Scope Bypass
None assigned as of 2026-07-03 cloud Unverified
None assigned as of 2026-07-03cloudCRITICALUnverified2026-07-03