VYPR
Vendor

Kong

Products
16
CVEs
19
Across products
22
Status
Private

Products

16

Recent CVEs

19
  • CVE-2023-39846CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

  • CVE-2020-35189CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2025-1087CriMay 9, 2025
    risk 0.54cvss epss 0.01

    Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to…

  • CVE-2021-27306HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.02

    An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.

  • CVE-2025-1353HigFeb 16, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in Kong Insomnia up to 10.3.0 and classified as critical. This issue affects some unknown processing in the library profapi.dll. The manipulation leads to untrusted search path. An attack has to be approached locally. The complexity of an attack is…

  • CVE-2023-26987MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

  • CVE-2026-13341HigJul 3, 2026
    risk 0.41cvss 7.4epss 0.00

    A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.

  • CVE-2026-18677MedAug 12, 2026
    risk 0.32cvss epss 0.00

    In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional,…

  • CVE-2026-6338MedJun 11, 2026
    risk 0.32cvss epss 0.00

    A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.

  • CVE-2026-18675MedAug 12, 2026
    risk 0.27cvss epss 0.00

    The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs. The panic terminates the…

  • CVE-2026-18676MedAug 12, 2026
    risk 0.26cvss epss 0.00

    The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the…

  • CVE-2023-2418LowApr 29, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be…

  • CVE-2020-11710CriApr 12, 2020
    risk 0.03cvss 9.8epss 0.33

    An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug…

  • CVE-2026-17578LowAug 5, 2026
    risk 0.00cvss epss 0.00

    Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a…

  • CVE-2026-16543HigJul 29, 2026
    risk 0.00cvss epss 0.00

    Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using…

  • CVE-2026-15228HigJul 29, 2026
    risk 0.00cvss epss 0.00

    Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without…

  • CVE-2023-40299HigOct 4, 2023
    risk 0.00cvss 7.8epss 0.00

    Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

  • CVE-2020-36661LowFeb 12, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is…

  • CVE-2012-6572Jun 21, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a…