{"schema_version": "1.6.1", "id": "CVE-2026-74848", "summary": "Cross-user response poisoning in serverless plugins", "details": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX.\n\nAn attacker could make other clients receive attacker-chosen or other users' responses on serverless-plugin routes.\n\n\n\n\nThis issue affects Apache APISIX: from 2.12.0 through 3.17.0.\n\n\n\nUsers are recommended to upgrade to version 3.18.0, which fixes the issue.", "affected": [{"ranges": [{"type": "SEMVER", "events": [{"introduced": "2.12.0"}, {"last_affected": "2.12.0"}]}]}], "references": [{"type": "WEB", "url": "https://lists.apache.org/thread/xdgpszmw8dw4wvmfxy043d83m150kx3n"}]}