github.com/kumahq/kuma/v2
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/kumahq/kuma/v2page 1 of 1
- CVE-2026-18676MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.13.52026-08-12
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fe…
- CVE-2026-18678MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.13.72026-08-12
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the opera…
- CVE-2026-18679MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2.13.72026-08-12
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connect…
- CVE-2026-45021MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.13.52026-05-28
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any…
- CVE-2026-50166MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.13.72026-07-16
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, a kumactl profile manually configured for an HTTPS control plane without --ca-cert…
- CVE-2026-52724MEDIUMCVSS 5.8EG 5.8✓ Fixed in 2.13.72026-07-16
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2.9.16, 2.11.14, 2.12.11, and 2.13.7, Universal mode kuma-dp connections to an HTTPS control plane disable TLS peer veri…
Check whether github.com/kumahq/kuma/v2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/kumahq/kuma/v2 CVEs against the assets you own.
Start Free Scan →