maven package report

Is apache/apisix safe?

5 known vulnerabilities, worst severity CRITICAL.

cvss
9.8

how bad it is if exploited, out of 10

epss
96.1%

chance of exploitation in the next 30 days

xyz score
7.7

CyberXYZ composite, and a working exploit is published

fig. 01 — CVE-2022-24112, the advisory selected below

// advisories

CVE-2022-24112

CRITICAL

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of

Affected
[object Object], [object Object]
Fixed in
not stated
Weakness
CWE-290
Published
2022-02-11
Source
NVD

NVDMITREreferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:41 UTC. The most recent advisory here was published 2025-10-31. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is apache/apisix safe? maven package security report | CyberXYZ