PT-2026-68094 · Kong · Kong Event Gateway
CVE-2026-17578
·
Published
2026-08-05
·
Updated
2026-08-05
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/U:Amber |
Name of the Vulnerable Software and Affected Versions
Kong Event Gateway versions 1.0.0 through 1.1.1
Kong Event Gateway version 1.2.0
Description
When the AWS IAM encryption feature is enabled, the software fails to enforce key rotation before reaching the NIST SP 800-38D recommended usage limit for AES-GCM encryption keys using random nonces. A nonce is a unique number used once in a cryptographic communication to prevent replay attacks. If messages are sent at a sustained high rate without key rotation, which previously only occurred during an instance reboot, the probability of a nonce collision increases. An authorized consumer detecting such a collision can recover portions of plaintext from the affected messages.
Recommendations
Update Kong Event Gateway versions 1.0.0 through 1.1.1 to version 1.1.2.
Update Kong Event Gateway version 1.2.0 to version 1.2.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kong Event Gateway