github.com/kumahq/kuma
🐻 The multi-zone service mesh for containers, Kubernetes and VMs. Built with Envoy. CNCF Sandbox Project.
Activity
- Latest release
- 3y ago
- Total releases
- 3
- Cadence
- ~8 months
- Last 12 months
- 0
Reach
- Stars
- 4.0k
Details
- First release
- Jun 30, 2021
| Version | Released | |
|---|---|---|
v1.8.1
minor
4 CVEs
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. References
Updated Aug 13, 2026 · Source: OSV.dev
GHSA-9wmc-rg4h-28wv
Oct 17, 2023
github.com/kumahq/kuma affected by CVE-2023-44487
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactEnvoy and Go HTTP/2 protocol stack is vulnerable to the "Rapid Reset" class of exploits, which send a sequence of HEADERS frames optionally followed by RST_STREAM frames. This can be exercised if you use the builtin gateway and receive untrusted http2 traffic. Patcheshttps://github.com/kumahq/kuma/pull/8023 https://github.com/kumahq/kuma/pull/8001 https://github.com/kumahq/kuma/pull/8034 WorkaroundsDisable http2 on the gateway listener with a MeshProxyPatch or ProxyTemplate. Referenceshttps://github.com/advisories/GHSA-qppj-fm5r-hxr3 https://github.com/golang/go/issues/63417 https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76 https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/?sf269548684=1 https://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/edge Fixed in
2.0.8
2.1.8
2.2.4
2.3.3
2.4.3
References
Updated Oct 13, 2025 · Source: OSV.dev |
v1.8.1
minor
Dependencies (69)
+ 61 more |
|
v1.5.0-rc2
pre
4 CVEs
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. References
Updated Aug 13, 2026 · Source: OSV.dev
GHSA-9wmc-rg4h-28wv
Oct 17, 2023
github.com/kumahq/kuma affected by CVE-2023-44487
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactEnvoy and Go HTTP/2 protocol stack is vulnerable to the "Rapid Reset" class of exploits, which send a sequence of HEADERS frames optionally followed by RST_STREAM frames. This can be exercised if you use the builtin gateway and receive untrusted http2 traffic. Patcheshttps://github.com/kumahq/kuma/pull/8023 https://github.com/kumahq/kuma/pull/8001 https://github.com/kumahq/kuma/pull/8034 WorkaroundsDisable http2 on the gateway listener with a MeshProxyPatch or ProxyTemplate. Referenceshttps://github.com/advisories/GHSA-qppj-fm5r-hxr3 https://github.com/golang/go/issues/63417 https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76 https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/?sf269548684=1 https://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/edge Fixed in
2.0.8
2.1.8
2.2.4
2.3.3
2.4.3
References
Updated Oct 13, 2025 · Source: OSV.dev |
v1.5.0-rc2
pre
Dependencies (65)
+ 57 more |
|
v1.2.1
initial
4 CVEs
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. References
Updated Aug 13, 2026 · Source: OSV.dev
GHSA-9wmc-rg4h-28wv
Oct 17, 2023
github.com/kumahq/kuma affected by CVE-2023-44487
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactEnvoy and Go HTTP/2 protocol stack is vulnerable to the "Rapid Reset" class of exploits, which send a sequence of HEADERS frames optionally followed by RST_STREAM frames. This can be exercised if you use the builtin gateway and receive untrusted http2 traffic. Patcheshttps://github.com/kumahq/kuma/pull/8023 https://github.com/kumahq/kuma/pull/8001 https://github.com/kumahq/kuma/pull/8034 WorkaroundsDisable http2 on the gateway listener with a MeshProxyPatch or ProxyTemplate. Referenceshttps://github.com/advisories/GHSA-qppj-fm5r-hxr3 https://github.com/golang/go/issues/63417 https://github.com/envoyproxy/envoy/security/advisories/GHSA-jhv4-f7mr-xx76 https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/?sf269548684=1 https://www.envoyproxy.io/docs/envoy/latest/configuration/best_practices/edge Fixed in
2.0.8
2.1.8
2.2.4
2.3.3
2.4.3
References
Updated Oct 13, 2025 · Source: OSV.dev |
v1.2.1
initial
Dependencies (56)
+ 48 more |