{"schema_version": "1.6.1", "id": "CVE-2026-63041", "summary": "attach-consumer-label does not strip client-supplied consumer-label headers", "details": "Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX.\n\nThis vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitise correctly.\n\n\nThis issue affects Apache APISIX: from 3.11.0 through 3.17.0.\n\n\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "3.11.0"}, {"last_affected": "3.11.0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/yg9tgn699rz7kyglw82m1775do8frjr4"}]}