CVE•Published 2026-08-05•Modified 2026-08-31•0 articles on news•4 live references•NVD data

CVE-2026-17578

Vulnerability data via NVD (ingested)

CVSS v3.1
—
EPSS percentile
5
Exploit Prediction Scoring System · top 95% of all CVEs
Description

Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a sustained high rate without key rotation, which only occurs on reboot of the Kong Event Gateway instance, the probability of a nonce collision becomes non-negligible. An authorized consumer who detects a nonce collision can recover parts of plaintext from the affected messages. New versions 1.1.2 and 1.2.1 enforce automatic key rotation before the recommended usage limit is reached.

Timeline
Published 2026-08-05
Modified 2026-08-31

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-17578 on GitHub.
We haven't classified any articles referencing CVE-2026-17578 yet. The external references above still apply.