Kong has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.7 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-14917High· 7.7A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false42CVE-2026-14916High· 7.7A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise42
Kong vulnerabilities
CVEs affecting Kong, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-14916High· 7.7A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise
A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing a…
▾ TwilightKong · Kong Enteprise GatewayEPSS 0.67%via NVD
CVE-2026-14917High· 7.7A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false
A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is explicitly set to false. This option is enabled by default. When disabled, the plugin may extract the SAML identity f…
▾ TwilightKong · Kong Enterprise GatewayEPSS 0.69%via NVD