Kong provides API gateway and developer-tooling platforms that sit in the critical request path of microservices architectures and modern application stacks, positioning its vulnerabilities as high-impact to organizations that depend on it for traffic routing and lifecycle management. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the internet-facing and authentication-critical role of the gateway product. The recurring exposure centers on the core Kong Gateway product and its containerized variants, with durable signal in weakness classes including regular expression complexity, resource-consumption issues, and process-control flaws that reflect parser and request-handling complexity in a proxy-oriented codebase. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Konghq over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2020-11710CRITICAL An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is no | Apr 12, 2020 | 9.8 | 61 | NO | YES |
CVE-2020-36661HIGH A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The m | Feb 12, 2023 | 7.5 | 24 | NO | NO |
CVE-2021-27306HIGH An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT. | Mar 18, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-40299HIGH Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment v | Oct 4, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-2418MEDIUM A vulnerability was found in Konga 2.8.3 on Kong. It has been classified as problematic. This affects an unknown part of the component Login API. The manipulation leads to insuffic | Apr 29, 2023 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Konghq.
Media articles that mention a CVE ID that affects a product developed by Konghq — matched by CVE ID, not by vendor name.