Com.ctrip.framework.apollo:apollo: CWE-20: Improper Input Validation in apolloconfig apollo (CVE-2026-59955)
Apollo ConfigService versions prior to 2.5.2 contain an improper input validation vulnerability that may allow unauthorized access to raw configuration data. The issue arises because requests to the /configfiles/raw/{appId}/{clusterName}/{namespace} endpoint are incorrectly parsed for authentication, causing the service to verify the wrong appId and potentially bypass signature verification. This vulnerability is fixed in version 2.5.2.
AI Analysis
Technical Summary
Apollo is a configuration management system used in microservice environments. In versions before 2.5.2, the ConfigService component improperly parses requests to the /configfiles/raw/{appId}/{clusterName}/{namespace} endpoint by treating the appId as 'raw' rather than the actual appId. This leads to the service looking up AccessKey secrets for 'raw' instead of the intended appId, which can cause the service to skip signature verification for the targeted appId. As a result, unauthorized users may gain access to raw configuration data even when AccessKey or management key authentication is enabled. The vulnerability is classified under CWE-20 (Improper Input Validation) and CWE-287 (Improper Authentication). It has a CVSS 3.1 score of 7.5 (high severity). The issue is resolved in Apollo version 2.5.2.
Potential Impact
Unauthorized users may access sensitive raw configuration data without proper authentication, potentially exposing configuration secrets or sensitive information. The vulnerability does not impact data integrity or availability but compromises confidentiality.
Mitigation Recommendations
Upgrade Apollo ConfigService to version 2.5.2 or later, where this improper input validation issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory stating the fix is in 2.5.2.
Com.ctrip.framework.apollo:apollo: CWE-20: Improper Input Validation in apolloconfig apollo (CVE-2026-59955)
Description
Apollo ConfigService versions prior to 2.5.2 contain an improper input validation vulnerability that may allow unauthorized access to raw configuration data. The issue arises because requests to the /configfiles/raw/{appId}/{clusterName}/{namespace} endpoint are incorrectly parsed for authentication, causing the service to verify the wrong appId and potentially bypass signature verification. This vulnerability is fixed in version 2.5.2.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apollo is a configuration management system used in microservice environments. In versions before 2.5.2, the ConfigService component improperly parses requests to the /configfiles/raw/{appId}/{clusterName}/{namespace} endpoint by treating the appId as 'raw' rather than the actual appId. This leads to the service looking up AccessKey secrets for 'raw' instead of the intended appId, which can cause the service to skip signature verification for the targeted appId. As a result, unauthorized users may gain access to raw configuration data even when AccessKey or management key authentication is enabled. The vulnerability is classified under CWE-20 (Improper Input Validation) and CWE-287 (Improper Authentication). It has a CVSS 3.1 score of 7.5 (high severity). The issue is resolved in Apollo version 2.5.2.
Potential Impact
Unauthorized users may access sensitive raw configuration data without proper authentication, potentially exposing configuration secrets or sensitive information. The vulnerability does not impact data integrity or availability but compromises confidentiality.
Mitigation Recommendations
Upgrade Apollo ConfigService to version 2.5.2 or later, where this improper input validation issue is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor advisory stating the fix is in 2.5.2.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h4pc-58cc-hc95
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-59955"]
- Ecosystems
- ["Maven"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a55ffa968715ace432fa026
Added to database: 07/14/2026, 09:21:45 UTC
Last enriched: 07/21/2026, 17:35:20 UTC
Last updated: 09/02/2026, 10:52:10 UTC
Views: 138
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.