ZoomEye[verified]@zoomeye_teamDisclosure
The post announces a newly disclosed CVE-2026-39999 in Apache APISIX, describing a JWT algorithm confusion authentication bypass and listing affected instances, but it does not provide exploitation details or mitigation information.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces the discovery of CVE-2026-39999, a JWT algorithm confusion vulnerability in Apache APISIX that permits authentication bypass, but does not provide proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
A tweet announces a critical CVE-2026-39999 vulnerability in Apache APISIX involving JWT algorithm confusion that could enable unauthorized authentication.
Lyrie.ai[verified]@lyrie_aiDisclosure
The notice announces a critical CVE‑2026‑39999 flaw in Apache APISIX—specifically a JWT algorithm confusion that permits authentication bypass—without providing a PoC, exploit, patch, or claim of active exploitation.
Lyrie.ai[verified]@lyrie_aiDisclosure
A new CVE (CVE-2026-39999) has been disclosed for Apache APISIX, describing a JWT Algorithm Confusion vulnerability that allows authentication bypass.
Can Artuc[verified]@canartucDisclosure
The post announces a JWT authentication bypass (CVE‑2026‑39999) in Apache APISIX versions 2.2‑3.16.0, with a fix available in 3.17.0, and urges checking your current deployment.
Can Artuc[verified]@canartucPatch
The advisory discloses an authentication-bypass flaw in APISIX’s jwt-auth plugin and announces a patch arriving in version 3.17.0, urging users to upgrade promptly.
Daily CyberSecurity@Daily_CyberSecPatch
APISIX authentication bypass (CVE‑2026‑39999) allows forging JWTs through algorithm confusion; upgrading to version 3.16.1 resolves the issue.