CVE-2026-15228: CWE-862
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and halting all ingress changes cluster-wide.
AI Analysis
Technical Summary
CVE-2026-15228 is a vulnerability in Kong Kubernetes Ingress Controller (KIC) that enables a user with privileges to create Secrets scoped to a namespace to trigger a cluster-wide ingress configuration denial of service. The issue arises because KIC aggregates CA-certificate Secrets from all namespaces it watches based solely on label selectors, lacking ingress-class or namespace restrictions. Since the CA-certificate primary key is derived from a user-controlled field in the Secret, an attacker can create duplicate CA-certificate IDs. This duplication causes Kong Gateway to reject the entire ingress configuration document, effectively halting all ingress updates across the cluster. The vulnerability affects versions 3.4.0, 3.5.0, and all versions from 3.4.0 up to but not including 3.4.18, and from 3.5.0 up to but not including 3.5.11. The CVSS 4.0 base score is 7.1, indicating high severity.
Potential Impact
An attacker with namespace-scoped Secret creation privileges can cause a cluster-wide denial of service on ingress configuration by creating Secrets with duplicate CA-certificate IDs. This leads Kong Gateway to reject the entire ingress configuration document, halting all ingress changes cluster-wide. This impacts availability of ingress routing and potentially disrupts application traffic managed by Kong Gateway.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is documented in the provided data. Until a fix is available, restrict namespace-scoped Secret creation privileges to trusted users only to reduce risk of exploitation.
CVE-2026-15228: CWE-862
Description
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and halting all ingress changes cluster-wide.
CVSS v4.0
Score 7.1high
Affected software
pkg:github/Kong/kubernetes-ingress-controllerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15228 is a vulnerability in Kong Kubernetes Ingress Controller (KIC) that enables a user with privileges to create Secrets scoped to a namespace to trigger a cluster-wide ingress configuration denial of service. The issue arises because KIC aggregates CA-certificate Secrets from all namespaces it watches based solely on label selectors, lacking ingress-class or namespace restrictions. Since the CA-certificate primary key is derived from a user-controlled field in the Secret, an attacker can create duplicate CA-certificate IDs. This duplication causes Kong Gateway to reject the entire ingress configuration document, effectively halting all ingress updates across the cluster. The vulnerability affects versions 3.4.0, 3.5.0, and all versions from 3.4.0 up to but not including 3.4.18, and from 3.5.0 up to but not including 3.5.11. The CVSS 4.0 base score is 7.1, indicating high severity.
Potential Impact
An attacker with namespace-scoped Secret creation privileges can cause a cluster-wide denial of service on ingress configuration by creating Secrets with duplicate CA-certificate IDs. This leads Kong Gateway to reject the entire ingress configuration document, halting all ingress changes cluster-wide. This impacts availability of ingress routing and potentially disrupts application traffic managed by Kong Gateway.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is documented in the provided data. Until a fix is available, restrict namespace-scoped Secret creation privileges to trusted users only to reduce risk of exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Kong
- Date Reserved
- 2026-07-09T10:50:51.533Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a1e549c2644c7f8b2d2d2
Added to database: 07/29/2026, 15:37:56 UTC
Last enriched: 07/29/2026, 15:52:23 UTC
Last updated: 07/30/2026, 00:52:01 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.