CVE-2026-6338: Kong Enterprise Gateway
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic.
Affected products
- Kong Kong Enterprise Gateway: from 3.4.0.0, before 3.4.3.27 (fixed in 3.4.3.27); from 3.10.0.0, before 3.10.0.12 (fixed in 3.10.0.12); from 3.11.0.0, before 3.11.0.12 (fixed in 3.11.0.12); from 3.12.0.0, before 3.12.0.7 (fixed in 3.12.0.7); from 3.13.0.0, before 3.13.0.5 (fixed in 3.13.0.5); from 3.14.0.0, before 3.14.0.4 (fixed in 3.14.0.4)
Published 2026-06-11. Last modified 2026-06-17.