github.com/kumahq/kuma
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/kumahq/kumapage 1 of 1
- CVE-2026-18676MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.7.252026-08-12
The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. Due to a CORS misconfiguration a cross-origin fe…
- CVE-2026-18678MEDIUMCVSS 5.5EG 5.52026-08-12
When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API tokens over the unverified connection. An attacker on the network path between the opera…
- CVE-2026-18679MEDIUMCVSS 5.8EG 5.82026-08-12
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connect…
- CVE-2026-45021MEDIUMCVSS 5.1EG 5.1✓ Fixed in 2.13.52026-05-28
Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any…
- CVE-2026-50166MEDIUMEG not assessed2026-07-16
kumactl connects to control plane without verifying TLS certificate when no CA is configured When an operator adds an HTTPS control plane profile to `kumactl` without providing a CA certificate, `kumactl` disables TLS verification and sen…
- CVE-2026-52724MEDIUMEG not assessed2026-07-16
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer veri…
Check whether github.com/kumahq/kuma is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/kumahq/kuma CVEs against the assets you own.
Start Free Scan →