NGINX Rift CVEs: Impact on Kong Gateway Open Source #14867
Closed
dndx
announced in
Announcements
Replies: 1 comment
-
|
Hello Kong Open Source Community, We have released the Kong Open Source 3.9.2 security release today, which contains fixes to all CVEs affecting Kong Open Source from the NGINX Rift series. Docker images are available at: https://hub.docker.com/r/kong/kong |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Dear Kong Community,
Kong is aware of the recently disclosed NGINX CVEs, including the issue publicly referred to as NGINX Rift. Here is our initial assessment of these CVEs and their impact on the Kong Gateway Open Source project.
Note: if you have an enterprise contract with Kong, please contact your support team to discuss impact on Kong's enterprise offerings. This advisory applies to the Open Source Kong releases only.
Kong is actively working on a 3.9.2 security release for the Open Source project and will publish it as soon as practical. The release will be announced in this discussion thread once it becomes available.
This page will be kept up to date as new information and findings regarding these CVEs emerge.
Updates:
ngx_http_rewrite_modulevulnerabilityrewritedirective which is necessary for triggering the vulnerability. Furthermore, Kong’s rewrite functionality is not performed via thengx_http_rewrite_module.ngx_http_scgi_moduleandngx_http_uwsgi_modulevulnerabilityngx_http_scgi_moduleorngx_http_uwsgi_moduleby default.ngx_http_ssl_modulevulnerabilityngx_http_charset_modulevulnerabilityngx_http_proxy_v2_modulevulnerabilityngx_http_proxy_v2_modulewas introduced in a later NGINX release and is not present in this version.ngx_quic_modulevulnerabilityngx_http_rewrite_modulevulnerability (aka NGINX PoolSlip)rewritedirective which is necessary for triggering the vulnerability. Furthermore, Kong’s rewrite functionality is not performed via thengx_http_rewrite_module.Footnotes
Kong Open Source is not vulnerable to CVE-2026-42926, see explanations above. ↩
Beta Was this translation helpful? Give feedback.
All reactions