CVE-2026-75005

Summary

Inefficient Algorithmic Complexity vulnerability in Apache APISIX.

A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count routes.

This issue affects Apache APISIX: 3.17.0.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache APISIX3.17.0affected

Weaknesses

  • CWE-407: CWE-407 Inefficient Algorithmic Complexity

ADP Enrichment

CVE Program Container

Additional References

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References