CVE-2026-94250

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
Full discourse1 post
  • LinuxSecurity@lnxsec

    A gateway can enforce authentication perfectly and still fall over before authentication becomes the interesting question. CVE-2026-94250 is a useful reminder that API gateway security is also resource accounting. When APISIX exposes the batch-requests endpoint, one external request can cause the gateway to assemble and retain work for multiple internal requests. On affected releases, that aggregation can push a worker into out-of-memory failure. That turns a convenience feature into an availability boundary. The security review cannot stop at “who can reach the API?” It also has to ask “how much work can one reachable request force the gateway to perform?” **In practical terms, it is a good time to:** - inventory APISIX instances and verify the running version, not just the package or image tag - identify routes exposing `/apisix/batch-requests` or a custom URI mapped to it - inspect `conf/config.yaml` and deployed route configuration for `batch-requests` and `public-api` - compare configured batch body, pipeline-item, and response-size limits with realistic production traffic - load-test batch routes while watching worker RSS, OOM events, latency, and upstream amplification How many gateway reviews in your environment explicitly test resource amplification rather than only authentication and routing? #LinuxSecurity #APISIX #CloudSecurity #DevSecOps #InfrastructureSecurity https://linuxsecurity.com/news/security-vulnerabilities/apisix-denial-of-service-attack-batch-requests

    0000072
    4.5K followersView on X

Explore more