{"api_version":"1","generated_at":"2026-10-04T01:01:10+00:00","cve":"CVE-2026-18675","urls":{"html":"https://cve.report/CVE-2026-18675","api":"https://cve.report/api/cve/CVE-2026-18675.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18675","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18675"},"summary":{"title":"Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid","description":"The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.\n\n\n\nThe panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token\n\n\n\nA single request is a transient interruption; sustaining an outage requires repeated requests.","state":"PUBLISHED","assigner":"Kong","published_at":"2026-08-12 19:17:30","updated_at":"2026-08-31 19:22:43"},"problem_types":["CWE-248","CWE-704","CWE-248 CWE-248 Uncaught Exception","CWE-704 CWE-704 Incorrect Type Conversion or Cast"],"metrics":[{"version":"4.0","source":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/kumahq/kuma/pull/17470","name":"https://github.com/kumahq/kuma/pull/17470","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/security/advisories/GHSA-5mxq-7xq4-3vx8","name":"https://github.com/kumahq/kuma/security/advisories/GHSA-5mxq-7xq4-3vx8","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17465","name":"https://github.com/kumahq/kuma/pull/17465","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17471","name":"https://github.com/kumahq/kuma/pull/17471","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17468","name":"https://github.com/kumahq/kuma/pull/17468","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://developer.konghq.com/mesh/changelog/","name":"https://developer.konghq.com/mesh/changelog/","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17467","name":"https://github.com/kumahq/kuma/pull/17467","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17472","name":"https://github.com/kumahq/kuma/pull/17472","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/kumahq/kuma/pull/17469","name":"https://github.com/kumahq/kuma/pull/17469","refsource":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18675","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18675","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.7.29 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.8.0 2.9.19 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.10.0 2.11.18 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.12.0 2.12.14 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.13.0 2.13.10 semver","platforms":["Linux"]},{"source":"CNA","vendor":"Kong Inc.","product":"Kong Mesh","version":"affected 2.14.0 2.14.2 semver","platforms":["Linux"]}],"timeline":[{"source":"CNA","time":"2026-08-01T16:58:00.000Z","lang":"en","value":"Kong Mesh patched releases published"}],"solutions":[{"source":"CNA","title":"","value":"Upgrade to Kong Mesh 2.7.29, 2.9.19, 2.11.18, 2.12.14, 2.13.10 or 2.14.2, whichever matches your release line. In patched versions the validator rejects a non-string kid header and the dataplane server recovers from handler panics.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Restrict network access to the dataplane (xDS) gRPC port to trusted data planes.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"https://hackerone.com/0ricky","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"18675","cve":"CVE-2026-18675","epss":"0.003840000","percentile":"0.314420000","score_date":"2026-09-01","updated_at":"2026-09-02 00:10:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-18675","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-13T15:28:24.304122Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-13T15:28:44.341Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["kuma-cp"],"platforms":["Linux"],"product":"Kong Mesh","vendor":"Kong Inc.","versions":[{"lessThan":"2.7.29","status":"affected","version":"0","versionType":"semver"},{"lessThan":"2.9.19","status":"affected","version":"2.8.0","versionType":"semver"},{"lessThan":"2.11.18","status":"affected","version":"2.10.0","versionType":"semver"},{"lessThan":"2.12.14","status":"affected","version":"2.12.0","versionType":"semver"},{"lessThan":"2.13.10","status":"affected","version":"2.13.0","versionType":"semver"},{"lessThan":"2.14.2","status":"affected","version":"2.14.0","versionType":"semver"}]}],"configurations":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>You are affected if any control plane has its dataplane (xDS) gRPC server reachable by an untrusted party.</p><p>You are not affected if the dataplane server is reachable only by trusted data planes on an isolated network.</p>"}],"value":"You are affected if any control plane has its dataplane (xDS) gRPC server reachable by an untrusted party.\n\n\n\nYou are not affected if the dataplane server is reachable only by trusted data planes on an isolated network."}],"credits":[{"lang":"en","type":"finder","value":"https://hackerone.com/0ricky"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>The dataplane token validator in <code>kuma-cp</code> performs an unchecked Go type assertion on the JWT <code>kid</code> header. A token whose <code>kid</code> is a JSON number decodes as a <code>float64</code> and triggers a runtime panic before any signature, claims, or authorization check runs.</p><p>The panic terminates the entire <code>kuma-cp</code> process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token</p><p>A single request is a transient interruption; sustaining an outage requires repeated requests.</p>"}],"value":"The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.\n\n\n\nThe panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token\n\n\n\nA single request is a transient interruption; sustaining an outage requires repeated requests."}],"impacts":[{"descriptions":[{"lang":"en","value":"Denial of Service"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.3,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-248","description":"CWE-248 Uncaught Exception","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-704","description":"CWE-704 Incorrect Type Conversion or Cast","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T18:36:17.377Z","orgId":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","shortName":"Kong"},"references":[{"name":"Upstream advisory GHSA-5mxq-7xq4-3vx8","tags":["vendor-advisory"],"url":"https://github.com/kumahq/kuma/security/advisories/GHSA-5mxq-7xq4-3vx8"},{"name":"kumahq/kuma#17465 (master)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17465"},{"name":"kumahq/kuma#17468 (release-2.14 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17468"},{"name":"kumahq/kuma#17467 (release-2.13 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17467"},{"name":"kumahq/kuma#17471 (release-2.12 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17471"},{"name":"kumahq/kuma#17469 (release-2.11 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17469"},{"name":"kumahq/kuma#17470 (release-2.9 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17470"},{"name":"kumahq/kuma#17472 (release-2.7 backport)","tags":["patch"],"url":"https://github.com/kumahq/kuma/pull/17472"},{"name":"Kong Product Security Advisories","tags":["release-notes"],"url":"https://developer.konghq.com/mesh/changelog/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Upgrade to Kong Mesh 2.7.29, 2.9.19, 2.11.18, 2.12.14, 2.13.10 or 2.14.2, whichever matches your release line. In patched versions the validator rejects a non-string <code>kid</code> header and the dataplane server recovers from handler panics.</p>"}],"value":"Upgrade to Kong Mesh 2.7.29, 2.9.19, 2.11.18, 2.12.14, 2.13.10 or 2.14.2, whichever matches your release line. In patched versions the validator rejects a non-string kid header and the dataplane server recovers from handler panics."}],"source":{"discovery":"EXTERNAL"},"timeline":[{"lang":"en","time":"2026-08-01T16:58:00.000Z","value":"Kong Mesh patched releases published"}],"title":"Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Restrict network access to the dataplane (xDS) gRPC port to trusted data planes.</p>"}],"value":"Restrict network access to the dataplane (xDS) gRPC port to trusted data planes."}]}},"cveMetadata":{"assignerOrgId":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","assignerShortName":"Kong","cveId":"CVE-2026-18675","datePublished":"2026-08-12T18:36:17.377Z","dateReserved":"2026-08-03T15:20:42.168Z","dateUpdated":"2026-08-13T15:28:44.341Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 19:17:30","lastModifiedDate":"2026-08-31 19:22:43","problem_types":["CWE-248","CWE-704","CWE-248 CWE-248 Uncaught Exception","CWE-704 CWE-704 Incorrect Type Conversion or Cast"],"metrics":{"cvssMetricV40":[{"source":"02762ae7-200e-4b20-9b2b-a77d5b8fc4cb","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-13T15:28:24.304122Z","id":"CVE-2026-18675","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18675","Ordinal":"1","Title":"Kong Mesh: control plane denial of service via a malformed datap","CVE":"CVE-2026-18675","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18675","Ordinal":"1","NoteData":"The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.\n\n\n\nThe panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token\n\n\n\nA single request is a transient interruption; sustaining an outage requires repeated requests.","Type":"Description","Title":"Kong Mesh: control plane denial of service via a malformed datap"}]}}}