ctrip has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 7.5 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-59955High· 7.5Apollo ConfigService access key authentication bypass via raw config file appId parsing41CVE-2026-59954High· 7.5Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching41CVE-2025-32781Medium· 6.5Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center36
ctrip vulnerabilities
CVEs affecting ctrip, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-59955High· 7.5Apollo ConfigService access key authentication bypass via raw config file appId parsing
Apollo ConfigService access key authentication bypass via raw config file appId parsing
▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2026-59954High· 7.5Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching
▾ Twilightctrip · com.ctrip.framework.apollo:apolloEPSS 0.57%via GHSA
CVE-2025-32781Medium· 6.5Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
Apollo Portal: There is a risk of unauthorized access to the Apollo configuration center
▾ Sunlitctrip · com.ctrip.framework.apollo:apolloEPSS 0.41%via GHSA