PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6338 Kong CVE debrief

A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.

Vendor
Kong
Product
Kong Enterprise Gateway
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-11
Original CVE updated
2026-06-11
Advisory published
2026-06-11
Advisory updated
2026-06-11

Who should care

Users of Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series should apply patches or mitigations to prevent exploitation.

Technical summary

The vulnerability has a CVSS score of 4.9 and is classified as MEDIUM severity. It allows attackers to smuggle and desynchronize HTTP requests, potentially leading to security issues.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply patches or updates provided by Kong Gateway Enterprise to fix the parsing flaw in the HTTP request processing pipeline.
  • Implement additional security measures to handle untrusted HTTP/1.1 traffic.

Evidence notes

The CVE record and NVD detail provide official information about the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6338 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6338

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6338 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6338

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://support.konghq.com/support/s/article/CVE-2026-6338

    02762ae7-200e-4b20-9b2b-a77d5b8fc4cb

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.