CVE-2026-15228 Details
Description
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The CA-certificate primary key is derived from a user-supplied field in the Secret. Duplicate CA-certificate IDs cause Kong Gateway to reject the entire configuration document and halting all ingress changes cluster-wide.
A denial-of-service vulnerability has been identified in Kong Kubernetes Ingress Controller (KIC) versions through 3.5.10 and 3.4.17. This issue allows users with namespace-scoped Secret creation privileges to disrupt cluster-wide ingress configurations. KIC gathers CA-certificate Secrets from all monitored namespaces using only a label selector, without considering ingress-class or namespace boundaries. The primary key for CA-certificates is derived from user-defined fields in the Secrets. When duplicate CA-certificate IDs are introduced, Kong Gateway rejects the entire configuration document, causing a halt in all ingress updates across the cluster until the conflicting Secret is removed.
Users can upgrade to Kong Kubernetes Ingress Controller versions 3.4.18 or 3.5.11, where this vulnerability has been patched. Additionally, it is recommended to restrict the watch scope to trusted namespaces and use Kubernetes RBAC to prevent untrusted users from creating or modifying Secrets with certain labels.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Kong/kubernetes-ingress-controller/security/advisories/GHSA-g9h6-h2xj-mf78 | Kong |
Weakness Enumeration
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | New CVE Received | Kong |
| Jul 29, 2026 | CVE Modified | CISA-ADP |