Kong Inc.
First CVE: May 9, 2025Active for: 1 year
3
CVEs Published
More CVEs Published than 9% of tracked CNAs
1.5
Avg CVEs / Year
More Avg CVEs / Year than 8% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Kong Inc. as a CNA, 0.0% affect products that Kong Inc. develops as a vendor.
100.0%
Self-reported: 0Third-party: 3
Of all the CVEs published that affect products developed by Kong Inc., 0.0% are self-published by Kong Inc. as a CNA.
100.0%
Self-published: 0Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Kong Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2025
14 months ago
Most Recent CVE
Jul 3, 2026
21 days ago
Top CVEs
All CVEs published by Kong Inc. as a CNA, regardless of affected vendor or product.
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13341HIGH A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection a | Jul 3, 2026 | 7.4 | 35 | NO | NO |
CVE-2025-1087CRITICAL Kong Insomnia Desktop Application before 11.0.2 contains a template injection vulnerability that allows attackers to execute arbitrary code. The vulnerability exists due to insuffi | May 9, 2025 | 9.3 | 30 | NO | NO |
CVE-2026-6338MEDIUM A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing | Jun 11, 2026 | 4.9 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA3 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (33.3%)
Unknown0 (0.0%)
Required1 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Kong Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Kong Inc. as a CNA — matched by CVE ID, not by organization name.