
Apache APISIX CVE-2026-31923: Openid-connect tls_verify disabled by default https://www.openwall.com/lists/oss-security/2026/04/14/1 CVE-2026-31924: Plugin tencent-cloud-cls log export uses plaintext HTTP https://www.openwall.com/lists/oss-security/2026/04/14/2 CVE-2026-31908: forward auth plugin allows header injection https://www.openwall.com/lists/oss-security/2026/04/14/3
Post summary
The text announces several new CVEs affecting Apache APISIX with brief technical descriptions, but provides no PoC, exploit code, or patch information.

