PatchSiren

Kong Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18679

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T20:17:41.957Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The CVE-2026-18679 vulnerability in kuma-dp allows an on-path actor to intercept the dataplane authentication token and impersonate the control plane when TLS peer verification is disabled. This occu [truncated]

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18678

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T19:17:31.323Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. CVE-2026-18678 is a vulnerability in kumactl that occurs when an operator adds an HTTPS control plane profile without providing a CA certificate, causing kumactl to disable TLS verification and send [truncated]

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18677

In Kong Mesh running in universal mode, a vulnerability allows dataplane tokens to be bound to any workload, potentially leading to unauthorized SPIFFE identity assignments. Organizations should verify their MeshIdentity configurations and dataplane token bindings to prevent this issue. The CVE record was published on 2026-08-12T19:17:31.063Z and has not been modified since then. The NVD entry is currentl [truncated]

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18676

The default kuma-cp configuration in Kong Mesh exposes admin bootstrap token and signing keys to any webpage visited by the operator while the control plane is reachable. This is due to a CORS misconfiguration allowing cross-origin fetch() requests from malicious pages to return admin JWT and signing material. Operators and administrators of Kong Mesh environments, especially those with shared or untruste [truncated]

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18675

The CVE-2026-18675 vulnerability affects the kuma-cp component, specifically the dataplane token validator. This vulnerability is caused by an unchecked Go type assertion on the JWT kid header, which can lead to a runtime panic and terminate the kuma-cp process, HTTP API, health and readiness endpoints, and xDS. The vulnerability can be triggered by an unauthenticated attacker with a malformed token. The [truncated]

MEDIUM Kong Inc. CVE published 2026-08-12

CVE-2026-18673

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T19:17:30.480Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The vulnerability affects organizations using kuma-dp with Envoy admin API on Unix domain sockets, allowing an attacker with network access to port 9902 to read Envoy and data plane configuration wit [truncated]