CVE-2026-16543: CWE-862
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and halting all ingress changes cluster-wide.
AI Analysis
Technical Summary
CVE-2026-16543 is a vulnerability in Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) that allows a user with namespace-scoped Secret creation privileges to induce a cluster-wide denial of service on ingress configuration. The KIC aggregates CA-certificate Secrets from all watched namespaces based solely on label selectors, lacking ingress-class or namespace restrictions. Since the CA-certificate primary key is derived from a user-controlled field in the Secret, an attacker can create duplicate CA-certificate IDs. These duplicates cause Kong Gateway to reject the entire ingress configuration document, stopping all ingress changes across the cluster. This vulnerability affects versions =2.1.0, >=2.1.0 <2.1.9, =2.2.0, >=2.2.0 <2.2.3, and versions <2.0.11. No official remediation or patch is currently documented.
Potential Impact
An attacker with the ability to create Secrets scoped to a namespace can cause a denial of service affecting the entire cluster's ingress configuration. This results in Kong Gateway rejecting all ingress configuration changes, potentially disrupting all ingress traffic managed by the controller. The impact is cluster-wide despite the attacker having only namespace-scoped privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Secret creation privileges carefully and monitor for suspicious Secret creation activities that could lead to duplicate CA-certificate IDs. Consider limiting label selectors or namespace watching scope if configurable. No official patch or workaround is currently documented.
CVE-2026-16543: CWE-862
Description
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and halting all ingress changes cluster-wide.
CVSS v4.0
Score 7.1high
Affected software
pkg:github/Kong/kong-operatorRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16543 is a vulnerability in Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) that allows a user with namespace-scoped Secret creation privileges to induce a cluster-wide denial of service on ingress configuration. The KIC aggregates CA-certificate Secrets from all watched namespaces based solely on label selectors, lacking ingress-class or namespace restrictions. Since the CA-certificate primary key is derived from a user-controlled field in the Secret, an attacker can create duplicate CA-certificate IDs. These duplicates cause Kong Gateway to reject the entire ingress configuration document, stopping all ingress changes across the cluster. This vulnerability affects versions =2.1.0, >=2.1.0 <2.1.9, =2.2.0, >=2.2.0 <2.2.3, and versions <2.0.11. No official remediation or patch is currently documented.
Potential Impact
An attacker with the ability to create Secrets scoped to a namespace can cause a denial of service affecting the entire cluster's ingress configuration. This results in Kong Gateway rejecting all ingress configuration changes, potentially disrupting all ingress traffic managed by the controller. The impact is cluster-wide despite the attacker having only namespace-scoped privileges.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Secret creation privileges carefully and monitor for suspicious Secret creation activities that could lead to duplicate CA-certificate IDs. Consider limiting label selectors or namespace watching scope if configurable. No official patch or workaround is currently documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Kong
- Date Reserved
- 2026-07-22T09:53:31.062Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a25599c2644c7f8bbd1f9
Added to database: 07/29/2026, 16:07:53 UTC
Last enriched: 07/29/2026, 16:22:30 UTC
Last updated: 07/29/2026, 21:18:59 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.