VYPR

Vendor CVEs

Kong

All CVEs

23 total · sorted by risk
  • CVE-2023-39846CriAug 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.

  • CVE-2020-35189CriDec 17, 2020
    risk 0.64cvss 9.8epss 0.02

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

  • CVE-2025-1087CriMay 9, 2025
    risk 0.54cvss —epss 0.01

    Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insufficient validation of user-supplied input when processing template strings, which can lead to…

  • CVE-2026-45221HigSep 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Konga before 2.1.0 contains a privilege escalation vulnerability that allows low-privileged local attackers to execute arbitrary code by planting attacker-controlled OpenSSL configuration or library files in a hardcoded filesystem path absent from default installations. On…

  • CVE-2026-14916HigSep 16, 2026
    risk 0.50cvss —epss 0.01

    A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of…

  • CVE-2026-14917HigSep 16, 2026
    risk 0.50cvss —epss 0.01

    A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity from an unsigned assertion and authenticate…

  • CVE-2021-27306HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.02

    An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.

  • CVE-2025-1353HigFeb 16, 2025
    risk 0.46cvss 7.0epss 0.00

    A vulnerability was found in Kong Insomnia up to 10.3.0 and classified as critical. This issue affects some unknown processing in the library profapi.dll. The manipulation leads to untrusted search path. An attack has to be approached locally. The complexity of an attack is…

  • CVE-2023-26987MedMay 1, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue discovered in Konga 0.14.9 allows remote attackers to manipulate user accounts regardless of privilege via crafted POST request.

  • CVE-2026-13341HigJul 3, 2026
    risk 0.41cvss 7.4epss 0.00

    A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.

  • CVE-2026-18674HigAug 17, 2026
    risk 0.39cvss —epss 0.00

    On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global…

  • CVE-2026-18677MedAug 12, 2026
    risk 0.32cvss —epss 0.00

    In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS authenticator in kuma-cp validates that label only when the dataplane token is bound to a workload. Workload binding is optional,…

  • CVE-2026-6338MedJun 11, 2026
    risk 0.32cvss —epss 0.00

    A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.

  • CVE-2026-18675MedAug 12, 2026
    risk 0.27cvss —epss 0.00

    The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs. The panic terminates the…

  • CVE-2026-18676MedAug 12, 2026
    risk 0.26cvss —epss 0.00

    The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fetch() from a malicious page returns the…

  • CVE-2023-2418LowApr 29, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insufficiently random values. The complexity of an attack is rather high. The exploitability is told to be…

  • CVE-2026-17578LowAug 5, 2026
    risk 0.15cvss —epss 0.00

    Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a…

  • CVE-2020-11710CriApr 12, 2020
    risk 0.03cvss 9.8epss 0.33

    An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug…

  • CVE-2026-16543HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using…

  • CVE-2026-15228HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without…

  • CVE-2023-40299HigOct 4, 2023
    risk 0.00cvss 7.8epss 0.00

    Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

  • CVE-2020-36661LowFeb 12, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is…

  • CVE-2012-6572Jun 21, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a…