High
Apache APISIX could allow a remote attacker to bypass security restrictions, caused by improper input validation. By passing a specially-crafted JSON with a duplicate key, an attacker could exploit this vulnerability to bypass the body_schema validation in the request-validation plugin
Apache
Upgrade to the latest version of Apache APISIX, available from the Apache Web site.