← Vulnerability feed

Vulnerability record · CVE-2021-43557 · published 22 November 2021

CVE-2021-43557: Apache apisix command injection vulnerability

Apache · Apisix

The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same issue. And it may affect the developer's custom plugin.

7.5 CVSS 3.1 High EPSS 13% · top 3.8% CWE-77 · Command injection
7.5CVSS 3.1 base score, v2 5.0
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block list contains "^/internal/", a URI like `//internal/` can be used to bypass it. Some other plugins also have the same issue. And it may affect the developer's custom plugin.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43557 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-24112Apache APISIX batch-requests plugin auth bypass enables RCEThe batch-requests plugin in Apache APISIX can be abused to bypass the Admin API IP restriction because a code bug defeats the check that overrides t…KEVEPSS 96%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed9.8CVE-2022-25757Apache apisix improper input validation vulnerabilityIn Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSO…EPSS 2.5%9.1CVE-2026-31908Apache apisix vulnerabilityHeader injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious …EPSS 0.60%8.7CVE-2026-75005Apache apisix vulnerabilityInefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period…EPSS 0.74%7.8CVE-2025-27446Apache apisix incorrect permission assignment vulnerabilityIncorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listening file permissions in APISIX …EPSS 0.19%7.5CVE-2026-31923Apache apisix cleartext transmission vulnerabilityCleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configura…EPSS 0.37%7.5CVE-2025-62232Apache apisix sensitive information in log file vulnerabilitySensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2021-43557), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.