HTTP Request Smuggling Vulnerability in Kong Gateway by Kong
CVE-2026-6338
4.9MEDIUM
What is CVE-2026-6338?
A flaw in Kong Gateway's handling of HTTP/1.1 traffic can allow attackers to exploit the parsing process within its request processing pipeline. This vulnerability exposes the system to potential HTTP request smuggling attacks, enabling malicious users to interfere with the integrity of requests. As a result, it may lead to unauthorized access or manipulation of data within the affected versions of Kong Gateway.
Affected Version(s)
Kong Enterprise Gateway Linux 3.4.0.0 < 3.4.3.27
Kong Enterprise Gateway Linux 3.10.0.0 < 3.10.0.12
Kong Enterprise Gateway Linux 3.11.0.0 < 3.11.0.12
