Vulnerabilidades em Kong Inc.
8 resultadosAnálise Vexday
Kong Inc. apresenta 1 CVE crítica em sua base, relacionada a validação inadequada de entrada (CWE-20), sem registro de exploração ativa em campo. A vulnerabilidade não é recente, reduzindo o risco imediato, mas a natureza crítica da falha exige atenção na avaliação de patches e mitigações disponíveis.
CVE-2025-1087CRITICALArbitrary Code Execution in Kong Insomnia Desktop ApplicationEPSS 1.1%CVE-2026-18675MEDIUMKong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kidEPSS 0.4%CVE-2026-18674HIGHKong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifierEPSS 0.4%CVE-2026-18677MEDIUMKong Mesh: a dataplane token without a workload binding can claim any workload's SPIFFE identityEPSS 0.3%CVE-2026-18673MEDIUMKong Mesh: the kuma-dp readiness service exposes the Envoy admin API without authenticationEPSS 0.3%CVE-2026-18676MEDIUMKong Mesh: default control plane config leaks the admin token cross-origin via a CORS wildcard and localhost adminEPSS 0.2%CVE-2026-18679MEDIUMKong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configuredEPSS 0.1%CVE-2026-18678MEDIUMKong Mesh: kumactl connects to the control plane without verifying the TLS certificate when no CA is configuredEPSS 0.1%