CVE-2026-17578: Kong Event Gateway

Low severity, CVSS 2.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages. New versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.

Affected products

  • Kong Kong Event Gateway: from 1.0.0, before 1.1.2 (fixed in 1.1.2); from 1.2.0, before 1.2.1 (fixed in 1.2.1)

Published 2026-08-05. Last modified 2026-08-31.