CVE-2026-17578
Received Received - Intake

Kong Event Gateway AES-GCM Nonce Collision Vulnerability

Vulnerability report for CVE-2026-17578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Kong

Description

Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages. New versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-06
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
kong event_gateway From 1.0.0 (inc) to 1.1.1 (inc)
kong event_gateway 1.2.0
kong event_gateway 1.1.2
kong event_gateway 1.2.1
kong event_gateway 1.0.0
kong event_gateway From 1.1.0 (inc) to 1.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-323 Nonces should be used for the present occasion and only once.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-17578 affects Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 when AWS IAM encryption is enabled. The vulnerability occurs because the system does not rotate encryption keys before reaching the NIST SP 800-38D recommended usage limit for AES-GCM keys with random nonces. This can lead to nonce collisions if messages are sent at high rates without key rotation, which only happens during reboot.

Detection Guidance

Detection involves monitoring for sustained high message rates without key rotation in Kong Event Gateway instances using AWS IAM encryption. Check logs for nonce collision warnings or unusual decryption failures. Verify if your version is 1.0.0 through 1.1.1 or 1.2.0, as these are affected.

Impact Analysis

An authorized attacker could exploit this vulnerability to detect nonce collisions and recover parts of plaintext from encrypted messages. This could expose sensitive data if the affected messages contain confidential information.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information. Non-compliance risks include legal penalties and reputational damage.

Mitigation Strategies

Upgrade to versions 1.1.2 or 1.2.1 where automatic key rotation is enforced. If upgrading isn't immediate, restrict high-rate message producers and monitor for nonce collisions until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart