<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Kong Gateway (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/kong-gateway.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kong-gateway-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Kong Gateway (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:12 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2021-27306 – An improper access control vulnerability in the JWT plugin in Kong Gateway prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27306</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27306</guid>
    <pubDate>Thu, 18 Mar 2021 15:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27306</strong></p>
  <p>An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users access to authenticated routes without a valid token JWT.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27306">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11710 – An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11710</guid>
    <pubDate>Sun, 12 Apr 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11710</strong></p>
  <p>An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is n…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11710">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
