PatchSiren cyber security CVE debrief
CVE-2026-6338 Kong CVE debrief
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.
- Vendor
- Kong
- Product
- Kong Enterprise Gateway
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-11
- Original CVE updated
- 2026-06-11
- Advisory published
- 2026-06-11
- Advisory updated
- 2026-06-11
Who should care
Users of Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series should apply patches or mitigations to prevent exploitation.
Technical summary
The vulnerability has a CVSS score of 4.9 and is classified as MEDIUM severity. It allows attackers to smuggle and desynchronize HTTP requests, potentially leading to security issues.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply patches or updates provided by Kong Gateway Enterprise to fix the parsing flaw in the HTTP request processing pipeline.
- Implement additional security measures to handle untrusted HTTP/1.1 traffic.
Evidence notes
The CVE record and NVD detail provide official information about the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6338 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6338
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6338 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6338
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://support.konghq.com/support/s/article/CVE-2026-6338
02762ae7-200e-4b20-9b2b-a77d5b8fc4cb
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.