Browse all 3 CVE security advisories affecting kumahq. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-50166 | Kuma: kumactl connects to control plane without verifying TLS certificate when no CA is configured — kuma CWE-295 | 5.5 | Medium | 2026-09-15 |
| CVE-2026-52724 | kuma-dp connects to control plane without verifying TLS certificate when no CA is configured — kuma CWE-295 | 5.8 | Medium | 2026-09-15 |
| CVE-2026-45021 | Kuma: Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin — kuma CWE-346 | - | - | 2026-05-28 |
This page lists every published CVE security advisory associated with kumahq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.