Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a malformed Cookie header to skip rate limit checks and exceed thresholds intended to restrict costly model backend calls.
References
Configurations
No configuration.
History
17 Sep 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/higress-group/higress/issues/4599 - |
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 16:18
NVD link : CVE-2026-92790
Mitre link : CVE-2026-92790
CVE.ORG link : CVE-2026-92790
JSON object : View
Products Affected
No product.
CWE
CWE-703
Improper Check or Handling of Exceptional Conditions
