Nonce Collision Risk in Kong Event Gateway Products by Kong
CVE-2026-17578
2.3LOW
What is CVE-2026-17578?
Certain versions of the Kong Event Gateway fail to enforce key rotation prior to reaching the recommended usage limit for AES-GCM encryption keys. This issue arises particularly when AWS IAM encryption is employed. If messages are transmitted at a high, consistent rate without proper key rotation—which only happens upon rebooting the Kong Event Gateway instance—the likelihood of nonce collision increases significantly. An authorized consumer could potentially exploit a nonce collision to extract portions of the plaintext from the compromised messages. Versions 1.1.2 and 1.2.1 have been released to implement automatic key rotation to mitigate this risk.
Affected Version(s)
Kong Event Gateway 1.0.0 < 1.1.2
Kong Event Gateway 1.2.0 < 1.2.1
