Products: 5
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-17578

    Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement

    Last Modified: Aug 07, 2026
    Published: Aug 05, 2026

    CVE-2026-16543

    Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision

    Last Modified: Jul 30, 2026
    Published: Jul 29, 2026

    CVE-2026-15228

    Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision

    Last Modified: Jul 30, 2026
    Published: Jul 29, 2026

    CVE-2026-6338

    HTTP request smuggling in Kong Enteprise Gateway

    Last Modified: Jun 12, 2026
    Published: Jun 11, 2026

    CVE-2020-35189

    The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

    Last Modified: Nov 21, 2024
    Published: Dec 17, 2020
    Items Per Page