CVE-2026-92790 PUBLISHED

Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a malformed Cookie header to skip rate limit checks and exceed thresholds intended to restrict costly model backend calls.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor higress-group
Product higress
Versions Default: unaffected
  • affected from 0 to 2.2.4 (excl.)

Credits

  • George Chen finder

References

Problem Types

  • Improper Check or Handling of Exceptional Conditions CWE