Apache · Apache Apisix · CVE-2026-48895
**Name of the Vulnerable Software and Affected Versions**
Apache APISIX versions 3.0.0 through 3.16.0
**Description**
An open redirect issue exists where an attacker can manipulate client headers, specifically the Host header in the `cas-auth` plugin, to influence the CAS service URL. This can lead to the redirection of users to untrusted sites and potentially expose session tokens.
**Recommendations**
Upgrade to version 3.17.0.