Junglewise Threat Intelligence

CVE-2026-18679: GO-2026-6013 - kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

CVE-2026-18679 · Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: github.com/kumahq/kuma (Go), github.com/kumahq/kuma/v2 (Go). Vendors: Go.

Executive brief

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma

Affected products

  • Go github.com/kumahq/kuma
  • Go github.com/kumahq/kuma/v2

CVE identifiers

  • CVE-2026-18679
  • CVE-2026-52724

Related threats