Apache APISIX Auth Bypass Cluster Shows API Gateways Need Plugin-Level Review
Apache disclosed a cluster of APISIX authentication and identity plugin CVEs. The defensive priority is patching, plugin inventory, and validating what backend services trust from the gateway.
