CVE-2024-32638

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:apisix:3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:apisix:3.9.0:*:*:*:*:*:*:*

History

10 Jul 2025, 16:00

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/05/02/2 - () http://www.openwall.com/lists/oss-security/2024/05/02/2 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/ngvgxllw4zn4hgngkqw2o225kf9wotov - () https://lists.apache.org/thread/ngvgxllw4zn4hgngkqw2o225kf9wotov - Mailing List, Vendor Advisory
First Time Apache
Apache apisix
CPE cpe:2.3:a:apache:apisix:3.8.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:apisix:3.9.0:*:*:*:*:*:*:*

13 Feb 2025, 18:18

Type Values Removed Values Added
Summary Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue. Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forward-auth` plugin.This issue affects Apache APISIX: from 3.8.0, 3.9.0. Users are recommended to upgrade to version 3.8.1, 3.9.1 or higher, which fixes the issue.
CWE CWE-444

02 May 2024, 14:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/05/02/2 -

02 May 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-02 10:15

Updated : 2025-07-10 16:00


NVD link : CVE-2024-32638

Mitre link : CVE-2024-32638


JSON object : View

Products Affected

apache

  • apisix
CWE

No CWE.