Impact
The vulnerability arises when Kong Event Gateway does not enforce AES‑GCM key rotation before reaching the NIST SP 800‑38D recommended usage limit. Because the system uses random nonces, a sustained high message rate can cause a nonce collision before a reboot triggers key rotation. When a collision occurs an authorized consumer can detect the reuse and recover portions of the encrypted payload, leading to partial confidentiality compromise.
Affected Systems
Vendors: Kong – Event Gateway. Affected releases are Kong Event Gateway 1.0.0 through 1.1.1 and 1.2.0, which lack the automatic key‑rotation safeguard.
Risk and Exploitability
The CVSS score is 2.3 and no EPSS data is available; the vulnerability is not in the CISA KEV catalog. The attack vector requires an authenticated consumer with access to the encrypted stream and a scenario where messages are sent at a high sustained rate without intervening key rotation—typically only occurring when the gateway is rebooted. Consequently the exploitability is low but confidentiality can be compromised if the conditions are met.
OpenCVE Enrichment