Nonce Collision Risk in Kong Event Gateway Products by Kong
CVE-2026-17578

2.3LOW

Key Information:

Vendor

Kong

Vendor
CVE Published:
5 August 2026

What is CVE-2026-17578?

Certain versions of the Kong Event Gateway fail to enforce key rotation prior to reaching the recommended usage limit for AES-GCM encryption keys. This issue arises particularly when AWS IAM encryption is employed. If messages are transmitted at a high, consistent rate without proper key rotation—which only happens upon rebooting the Kong Event Gateway instance—the likelihood of nonce collision increases significantly. An authorized consumer could potentially exploit a nonce collision to extract portions of the plaintext from the compromised messages. Versions 1.1.2 and 1.2.1 have been released to implement automatic key rotation to mitigate this risk.

Affected Version(s)

Kong Event Gateway 1.0.0 < 1.1.2

Kong Event Gateway 1.2.0 < 1.2.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.