VYPR

kuma-cp

by Kong

CVEs (2)

  • CVE-2026-18677MedAug 12, 2026
    risk 0.32cvss epss

    In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional,…

  • CVE-2026-18676MedAug 12, 2026
    risk 0.26cvss epss

    The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the…