Executive brief
A vulnerability in the Kong Ingress Controller for Kubernetes allows users with limited permissions to access sensitive security credentials from other parts of the system. In multi-tenant environments, an attacker could steal TLS certificates and private keys belonging to other teams or applications. This could lead to unauthorized data decryption or the impersonation of secure services.
Technical details
A vulnerability exists in the Kong Ingress Controller (KIC) Gateway TLS translator when operating in 'managed' mode (default). The translator fails to perform critical status checks and ReferenceGrant validation for cross-namespace certificate references. An attacker with RBAC permissions to create or update Gateway resources in a low-privileged namespace can reference a Secret in a high-privileged namespace. This causes KIC to fetch the Secret and include its private key material in the Kong dataplane configuration, bypassing intended namespace isolation. The fix introduces mandatory ReferenceGrant validation and requires a 'Programmed: True' listener status for cross-namespace access.
Affected products
- Kong kubernetes-ingress-controller/v3 <= 3.4.13, >= 3.5.0, <= 3.5.6
- Kong kubernetes-ingress-controller/v2 <= 2.12.8
- Kong kubernetes-ingress-controller <= 1.3.4
Timeline
- 2026-05-13: disclosed: Initial publication by maintainers
- 2026-05-19: advisory: GitHub Advisory published/updated
References
- https://api.github.com/users/bugbunny-research
- https://github.com/bugbunny-research
- https://api.github.com/users/bugbunny-research/gists%7B/gist_id%7D
- https://api.github.com/users/bugbunny-research/repos
- https://avatars.githubusercontent.com/u/262839898?v=4
- https://api.github.com/users/bugbunny-research/events%7B/privacy%7D