CVE-2026-18675: Kong Mesh: control plane denial of service via a malformed dataplane token with a non-string JWT kid

Published Aug 12, 2026
·
Updated

The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as a float64 and triggers a runtime panic before any signature, claims, or authorization check runs.

The panic terminates the entire kuma-cp process, HTTP API, the health and readiness endpoints, and xDS. Unauthenticated access to the dataplane gRPC server can trigger the crash with a malformed token

A single request is a transient interruption; sustaining an outage requires repeated requests.

Affected Software

1 affected component
kong Kong Mesh (kuma-cp)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.7.29
  2. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.9.19
  3. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.11.18
  4. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.12.14
  5. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.13.10
  6. Upgrade

    Upgrade Kong Mesh to a version that resolves this vulnerability.

    Fixed in 2.14.2

Event History

Aug 12, 2026
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
RemedyDescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18675?

CVE-2026-18675 is rated with a risk score of 62, indicating a notable potential for denial of service.

2

How do I fix CVE-2026-18675?

To mitigate CVE-2026-18675, upgrade to the latest version of kong Kong Mesh that addresses the malformed dataplane token issue.

3

What types of systems are affected by CVE-2026-18675?

CVE-2026-18675 affects systems utilizing kong Kong Mesh, specifically the kuma-cp control plane.

4

What happens during a CVE-2026-18675 exploit?

Exploitation of CVE-2026-18675 can cause a runtime panic that terminates the entire kuma-cp process, leading to service disruption.

5

Who reported CVE-2026-18675?

CVE-2026-18675 was reported in the context of the kong Kong Mesh project and documented in their security advisories.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203