What is CVE-2026-17578?
CVE-2026-17578 affects Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0, where AES-GCM encryption keys with AWS IAM feature enabled are not rotated before reaching the NIST SP 800-38D recommended usage limit. This could weaken encryption security under sustained high-rate message traffic, so users should upgrade to a patched version and enforce key rotation policies.
Azərbaycanca: CVE-2026-17578 boşluğu Kong Event Gateway-in 1.0.0-1.2.0 versiyalarında AWS IAM şifrələməsi aktiv olduqda AES-GCM açarlarının NIST tövsiyə etdiyi istifadə limitinə çatdıqda açar rotasiyasını məcburi etməməsi ilə bağlıdır. Bu, yüksək sürətli mesaj axınında şifrələmə təhlükəsizliyini zəiflədə bilər; istifadəçilər gateway-i ən son versiyaya yeniləməli və açar rotasiyası siyasətlərini nəzərdən keçirməlidir.
FAQ2
Which versions of Kong Event Gateway are affected by CVE-2026-17578?
Kong Event Gateway versions 1.0.0 through 1.1.1 and version 1.2.0 are affected.
What should users do to protect against this vulnerability?
Users should upgrade to a patched version and enforce key rotation policies.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.