Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-17578— Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement

Quick assessment

Affected
Kong Kong Event Gateway
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kong Event Gateway是Kong公司的一款事件网关。 Kong Event Gateway 1.0.0至1.1.1版本和1.2.0版本存在加密问题漏洞,该漏洞源于在启用AWS IAM加密功能时,未在达到NIST SP 800-38D推荐的AES-GCM加密密钥随机nonce使用限制前强制密钥轮换,可能导致nonce碰撞,进而允许授权消费者恢复受影响消息的部分明文。

CVSS 2.3 · Low EPSS 0.24% · P14

Affected Version Matrix 2

VendorProduct Version RangeStatus
Kong Kong Event Gateway 1.0.0< 1.1.2 affected
1.2.0< 1.2.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17578

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kong Event Gateway AES-GCM nonce reuse due to missing key rotation enforcement
Source: CVE Program / CVE List V5
Vulnerability Description
Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages. New versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/AU:N/R:U/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
在加密中重用Nonce与密钥对
Source: CVE Program / CVE List V5
Vulnerability Title
Kong Event Gateway 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Kong Event Gateway是Kong公司的一款事件网关。 Kong Event Gateway 1.0.0至1.1.1版本和1.2.0版本存在加密问题漏洞,该漏洞源于在启用AWS IAM加密功能时,未在达到NIST SP 800-38D推荐的AES-GCM加密密钥随机nonce使用限制前强制密钥轮换,可能导致nonce碰撞,进而允许授权消费者恢复受影响消息的部分明文。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kong Kong Event Gateway 1.0.0 ~ 1.1.2 -

II. Public POCs for CVE-2026-17578

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17578

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-17578

No comments yet


Leave a comment