Skip to main content

October

· 4 min read

NG Production Release Update - APIsec_cloud_7.10.1.0 ( October 05, 2026 )​

This release expands APIsec’s support for modern API request and authentication patterns, including form-encoded and multipart requests, while improving the accuracy of sensitive-data classification. It also adds CVSS score change history and export capabilities and improves scan reliability, endpoint coverage, specification reloads, and scan startup performance.

What's New​

Broader Support for Form-Encoded, Multipart​

APIsec now correctly handles APIs and authentication flows that use form-encoded ( application/x-www-form-urlencoded ) or multipart request bodies. Requests that previously failed because the platform treated their bodies as JSON can now be sent with the expected encoding.

Impact​

  • File-upload (multipart) endpoints are exercised correctly
  • No configuration changes are required — the appropriate encoding and signing are applied automatically

Improvements​

Improved Data Sensitivity Classification​

APIsec now identifies sensitive parameters, including personal data (PII) and payment data (PCI), more accurately and applies sensitivity levels more consistently across all APIs. Parameter and endpoint sensitivity labels help the platform focus on sensitive-data findings, so improved classification means more relevant results.

Impact​

  • More reliable detection of sensitive fields, such as identifiers, card data, and credentials, based on parameter names
  • More consistent High/Critical sensitivity labeling across endpoints
  • Some parameters may have different sensitivity labels after this release as we reassess them. This is expected and reflects the improved classification. No action is required.

Complex Header Parameters Are No Longer Added as Instance Headers​

When an API specification defines a header parameter with a non-scalar schema, such as an object or array, APIsec no longer creates it as an instance-level header. Simple (scalar) header parameters continue to work as before. More granular, per-endpoint header customization is coming up next.

Impact​

  • Prevents complex header parameters from being incorrectly configured as instance-level headers
  • Preserves the existing behavior for simple header parameters

Blank Headers Are No Longer Sent​

An instance header configured without a value is now omitted from requests instead of being sent with an empty or null value.

Impact​

  • Prevents empty headers from being included in scan requests
  • Produces cleaner requests when optional header values are not configured
  • Reduces unexpected behavior caused by blank header values

More Accurate Request Bodies During Scans​

Request fields constrained by a pattern now receive a valid value matching that pattern instead of being left empty. This allows more requests to pass validation and reach the behavior under test.

Impact​

  • More generated requests comply with the API's defined validation rules
  • Reduces requests being rejected before the intended test can execute
  • Improves scan coverage for APIs that use pattern-constrained fields

Reliable Specification Reloads on Older Instances​

Reloading an API specification on long-standing instances now completes reliably.

Impact​

  • Improves the reliability of specification reloads on existing instances
  • Helps keep long-standing instances aligned with the latest API specification
  • Reduces the need to retry specification reload operations

Faster Scan Setup​

Part of the pre-scan analysis now runs in the background, reducing the time required to begin a scan without affecting scan coverage.

Impact​

  • Scans can begin sooner
  • Reduces the time spent waiting during scan initialization
  • Maintains existing scan coverage while improving scan startup performance