Apache · Apache Apisix · CVE-2026-75005
**Name of the Vulnerable Software and Affected Versions**
Apache APISIX version 3.17.0
**Description**
An inefficient algorithmic complexity issue exists where a single small request can cause a gateway worker to reach 100% CPU usage for an extended period when using `graphql-limit-count` routes.
**Recommendations**
Upgrade to version 3.18.0.