kumahq has 6 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The median CVSS is 5.7 (medium). None have a confirmed exploitation report. Most affected products: github.com/kumahq/kuma (2), github.com/kumahq/kuma/v2 (2), kuma (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.7
- Publish → KEV
- —
- Last 90 days
- 4 prev 2
Weakness classes
Products
- github.com/kumahq/kuma 2
- github.com/kumahq/kuma/v2 2
- kuma 2
Worst active — by depth score
CVE-2026-52724Medium· 5.8Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs32CVE-2026-50166Medium· 5.5Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs30CVE-2026-18679Mediumkuma-dp connects to control plane without verifying TLS certificate when no CA is configured28CVE-2026-18678Mediumkumactl connects to control plane without verifying TLS certificate when no CA is configured28CVE-2026-45021MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin28
kumahq vulnerabilities
CVEs affecting kumahq, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-52724Medium· 5.8Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer ve…
CVE-2026-50166Medium· 5.5Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-ce…
CVE-2026-18679Mediumkuma-dp connects to control plane without verifying TLS certificate when no CA is configured
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-18678Mediumkumactl connects to control plane without verifying TLS certificate when no CA is configured
kumactl connects to control plane without verifying TLS certificate when no CA is configured
CVE-2026-18676MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
CVE-2026-45021MediumDefault kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin