HTTP Request Smuggling Vulnerability in Kong Gateway by Kong
CVE-2026-6338

4.9MEDIUM

Key Information:

Vendor

Kong

Vendor
CVE Published:
11 June 2026

What is CVE-2026-6338?

A flaw in Kong Gateway's handling of HTTP/1.1 traffic can allow attackers to exploit the parsing process within its request processing pipeline. This vulnerability exposes the system to potential HTTP request smuggling attacks, enabling malicious users to interfere with the integrity of requests. As a result, it may lead to unauthorized access or manipulation of data within the affected versions of Kong Gateway.

Affected Version(s)

Kong Enterprise Gateway Linux 3.4.0.0 < 3.4.3.27

Kong Enterprise Gateway Linux 3.10.0.0 < 3.10.0.12

Kong Enterprise Gateway Linux 3.11.0.0 < 3.11.0.12

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.