github.com/kumahq/kuma/v2
🐻 The multi-zone service mesh for containers, Kubernetes and VMs. Built with Envoy. CNCF Sandbox Project.
Activity
- Latest release
- 4d ago
- Total releases
- 53
- Cadence
- ~daily
- Last 12 months
- 53
Reach
- Stars
- 4.0k
Details
- First release
- Nov 13, 2025
| Version | Released | |
|---|---|---|
v2.13.11
patch
|
v2.13.11
patch
Dependencies (91)
+ 83 more |
|
v2.12.15
patch
|
v2.12.15
patch
Dependencies (90)
+ 82 more |
|
v2.14.4
patch
|
v2.14.4
patch
Dependencies (92)
+ 84 more |
|
v2.14.3
patch
|
v2.14.3
patch
Dependencies (92)
+ 84 more |
|
v2.7.29
patch
|
v2.7.29
patch
Dependencies (86)
+ 78 more |
|
v2.11.18
patch
|
v2.11.18
patch
Dependencies (89)
+ 81 more |
|
v2.12.14
patch
|
v2.12.14
patch
Dependencies (90)
+ 82 more |
|
v2.13.10
patch
|
v2.13.10
patch
Dependencies (91)
+ 83 more |
|
v2.14.2
patch
|
v2.14.2
patch
Dependencies (92)
+ 84 more |
|
v2.14.1
patch
|
v2.14.1
patch
Dependencies (92)
+ 84 more |
|
v2.13.9
patch
|
v2.13.9
patch
Dependencies (91)
+ 83 more |
|
v2.12.13
patch
|
v2.12.13
patch
Dependencies (90)
+ 82 more |
|
v2.11.17
patch
|
v2.11.17
patch
Dependencies (89)
+ 81 more |
|
v2.7.28
patch
|
v2.7.28
patch
Dependencies (86)
+ 78 more |
|
v2.11.16
patch
|
v2.11.16
patch
Dependencies (89)
+ 81 more |
|
v2.14.0
minor
|
v2.14.0
minor
Dependencies (92)
+ 84 more |
|
v2.7.27
patch
|
v2.7.27
patch
Dependencies (86)
+ 78 more |
|
v2.13.8
patch
|
v2.13.8
patch
Dependencies (91)
+ 83 more |
|
v2.11.15
patch
|
v2.11.15
patch
Dependencies (89)
+ 81 more |
|
v2.12.12
patch
|
v2.12.12
patch
Dependencies (90)
+ 82 more |
|
v2.11.14
patch
|
v2.11.14
patch
Dependencies (89)
+ 81 more |
|
v2.13.7
patch
|
v2.13.7
patch
Dependencies (91)
+ 83 more |
|
v2.13.6
patch
2 CVEs
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.6
patch
Dependencies (91)
+ 83 more |
|
v2.12.11
patch
|
v2.12.11
patch
Dependencies (90)
+ 82 more |
|
v2.7.26
patch
|
v2.7.26
patch
Dependencies (86)
+ 78 more |
|
v2.11.13
patch
2 CVEs
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.11.13
patch
Dependencies (89)
+ 81 more |
|
v2.7.25
patch
2 CVEs
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.25
patch
Dependencies (86)
+ 78 more |
|
v2.12.10
patch
2 CVEs
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.10
patch
Dependencies (90)
+ 82 more |
|
v2.13.5
patch
2 CVEs
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.5
patch
Dependencies (91)
+ 83 more |
|
v2.13.4
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.4
patch
Dependencies (91)
+ 83 more |
|
v2.12.9
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.9
patch
Dependencies (90)
+ 82 more |
|
v2.11.12
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.11.12
patch
Dependencies (89)
+ 81 more |
|
v2.7.24
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.24
patch
Dependencies (86)
+ 78 more |
|
v2.13.3
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.3
patch
Dependencies (91)
+ 83 more |
|
v2.12.8
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.8
patch
Dependencies (90)
+ 82 more |
|
v2.11.11
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.11.11
patch
Dependencies (89)
+ 81 more |
|
v2.7.23
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.23
patch
Dependencies (86)
+ 78 more |
|
v2.10.11
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.10.11
patch
Dependencies (88)
+ 80 more |
|
v2.7.22
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.22
patch
Dependencies (86)
+ 78 more |
|
v2.12.7
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.7
patch
Dependencies (90)
+ 82 more |
|
v2.11.10
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.11.10
patch
Dependencies (89)
+ 81 more |
|
v2.13.2
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.2
patch
Dependencies (91)
+ 83 more |
|
v2.7.21
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.21
patch
Dependencies (86)
+ 78 more |
|
v2.13.1
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.1
patch
Dependencies (91)
+ 83 more |
|
v2.10.10
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.10.10
patch
Dependencies (88)
+ 80 more |
|
v2.11.9
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.11.9
patch
Dependencies (89)
+ 81 more |
|
v2.12.6
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.6
patch
Dependencies (90)
+ 82 more |
|
v2.13.0
minor
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.13.0
minor
Dependencies (91)
+ 83 more |
|
v2.12.5
patch
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.12.5
patch
Dependencies (90)
+ 82 more |
|
v2.7.20
initial
3 CVEs
CVE-2026-18676
GO-2026-5102
CVE-2026-45021
GHSA-3vcp-chfh-f6r2
Jul 22, 2026
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15. Fixed in
2.7.25
2.11.13
2.12.10
2.13.5
References
Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18678
GO-2026-6010
CVE-2026-50166
GHSA-v95x-xhq5-4929
Jul 22, 2026
kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kumactl connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev
CVE-2026-18679
GO-2026-6013
CVE-2026-52724
GHSA-wvmp-6r4v-j6cv
Jul 22, 2026
kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma kuma-dp connects to control plane without verifying TLS certificate when no CA is configured in github.com/kumahq/kuma. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.8.0 before v2.9.16. Fixed in
2.7.26
2.11.14
2.12.11
2.13.7
References Updated Aug 13, 2026 · Source: OSV.dev |
v2.7.20
initial
Dependencies (85)
+ 77 more |