CVE-2026-92790

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a malformed Cookie header to skip rate limit checks and exceed thresholds intended to restrict costly model backend calls.
Configurations

No configuration.

History

17 Sep 2026, 16:18

Type Values Removed Values Added
References () https://github.com/higress-group/higress/issues/4599 - () https://github.com/higress-group/higress/issues/4599 -

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-17 16:18


NVD link : CVE-2026-92790

Mitre link : CVE-2026-92790

CVE.ORG link : CVE-2026-92790


JSON object : View

Products Affected

No product.

CWE
CWE-703

Improper Check or Handling of Exceptional Conditions