Apache · Apache Apisix · CVE-2026-39999
**Name of the Vulnerable Software and Affected Versions**
Apache APISIX versions 2.2 through 3.16.0
**Description**
An authentication bypass by spoofing exists in the `jwt-auth` plugin. This issue, caused by JWT algorithm confusion, allows a remote attacker to completely bypass security restrictions and gain unauthorized access to protected information by forging tokens. Approximately 30,100 instances are identified globally.
**Recommendations**
Upgrade to version 3.17.0.
As a temporary mitigation, restrict the use of the `jwt-auth` plugin until the update is applied.