Executive brief
A security vulnerability has been identified in Kong Gateway Enterprise, a platform used to manage and secure API traffic. A flaw in how the gateway processes web requests could allow an attacker to interfere with the communication between the gateway and backend services. This could potentially lead to unauthorized access to data or the bypassing of security controls.
Technical details
Kong Gateway Enterprise is vulnerable to HTTP request smuggling (CWE-444) and request desynchronization. The root cause is a parsing flaw within Kong's HTTP request processing pipeline when handling untrusted HTTP/1.1 traffic. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests that are interpreted differently by the Kong Gateway and the backend servers it protects. This can result in the attacker 'smuggling' a request to the backend, potentially leading to security filter bypass or cache poisoning. The vulnerability affects the 3.4 and 3.10 through 3.14 release series.
Affected products
- Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, 3.14 series
Timeline
- 2026-06-11: advisory: NVD and vendor advisory published