---
id: CVE-2026-94220
title: >-
  Cross-Site request forgery (CSRF) vulnerability in feishu-auth and
  dingtalk-auth plugins in Apache APISIX.




  An attacker who can get a user to click a crafted link may cause that user's
  browser session on a protected route to be establi…
summary: >-
  Cross-Site request forgery (CSRF) vulnerability in feishu-auth and
  dingtalk-auth plugins in Apache APISIX.




  An attacker who can get a user to click a crafted link may cause that user's
  browser session on a protected route to be establi…
severity: low
cvss: 2.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'
cwe:
  - CWE-352
vendor: Apache Software Foundation
product: Apache APISIX
affected:
  - apache_apisix >= 3.17.0 <= 3.18.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T12:54:27.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94220'
references:
  - url: 'https://lists.apache.org/thread.html/bf5q45ddyr2hf3hxkt56dzjlttgpdg78'
    label: security@apache.org
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-01T11:42:53.819Z'
---

## Overview

Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX.



An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0.



Users are recommended to upgrade to version 3.19.0, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
