CVE-2026-31923 PUBLISHED

Apache APISIX: Openid-connect `tls_verify` field is disabled by default

Assigner: apache
Reserved: 10.03.2026 Published: 14.04.2026 Updated: 14.04.2026

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX.

This can occur due to ssl_verify in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0.

Users are recommended to upgrade to version 3.16.0, which fixes the issue.

Product Status

Vendor Apache Software Foundation
Product Apache APISIX
Versions Default: unaffected
  • affected from 0.7 to 3.15.0 (incl.)

Credits

  • Oleh Konko reporter

References

Problem Types

  • CWE-319 Cleartext Transmission of Sensitive Information CWE