PT-2026-68094 · Kong · Kong Event Gateway

CVE-2026-17578

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/U:Amber
Name of the Vulnerable Software and Affected Versions Kong Event Gateway versions 1.0.0 through 1.1.1 Kong Event Gateway version 1.2.0
Description When the AWS IAM encryption feature is enabled, the software fails to enforce key rotation before reaching the NIST SP 800-38D recommended usage limit for AES-GCM encryption keys using random nonces. A nonce is a unique number used once in a cryptographic communication to prevent replay attacks. If messages are sent at a sustained high rate without key rotation, which previously only occurred during an instance reboot, the probability of a nonce collision increases. An authorized consumer detecting such a collision can recover portions of plaintext from the affected messages.
Recommendations Update Kong Event Gateway versions 1.0.0 through 1.1.1 to version 1.1.2. Update Kong Event Gateway version 1.2.0 to version 1.2.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17578

Affected Products

Kong Event Gateway