CVE-2026-78242: Apache Software Foundation Apache APISIX

Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause the unmasked header value to be written to the log sink under a certain response structure.  This issue affects Apache APISIX: 3.17.0. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Affected products

Published 2026-10-01. Last modified 2026-10-01.