{"id":"GHSA-wvmp-6r4v-j6cv","summary":"kuma-dp connects to control plane without verifying TLS certificate when no CA is configured","details":"When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled. The dataplane authentication token is sent over this unverified connection\n\n## Impact\n\nAn on-path attacker can intercept the dataplane authentication token and impersonate the control plane to the data plane, allowing them to inject a forged bootstrap configuration and take over the proxy\n\n## Affected configurations\n\n- Universal mode `kuma-dp` started against an HTTPS control plane without `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT` unset)\n\n## Not affected\n\n- Kubernetes installs done through the standard installers (`kumactl install control-plane` or the official Helm chart). In both cases the control plane's mutating admission webhook injects `KUMA_CONTROL_PLANE_CA_CERT` into every sidecar at pod admission, so each `kuma-dp` starts with the CA already configured\n\n## Workarounds\n\nSet `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT`) on every Universal mode data plane and point it at the control plane's serving CA. Alternatively, terminate the control plane behind a publicly trusted certificate; the patched releases will verify successfully against the operating system trust store with no further configuration\n\n## Resources\n\n- Fix: https://github.com/kumahq/kuma/pull/16777","aliases":["CVE-2026-18679","CVE-2026-52724","GO-2026-6013"],"modified":"2026-08-13T03:55:33.245676019Z","published":"2026-07-16T20:09:12Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-16T20:09:12Z","nvd_published_at":null,"cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"https://github.com/kumahq/kuma/security/advisories/GHSA-wvmp-6r4v-j6cv"},{"type":"WEB","url":"https://github.com/kumahq/kuma/pull/16777"},{"type":"WEB","url":"https://github.com/kumahq/kuma/commit/2ecadac1aa2fd8cded4c2ab768949f4c2ec83e2a"},{"type":"PACKAGE","url":"https://github.com/kumahq/kuma"}],"affected":[{"package":{"name":"github.com/kumahq/kuma/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.7.26"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}},{"package":{"name":"github.com/kumahq/kuma/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.8.0"},{"fixed":"2.9.16"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}},{"package":{"name":"github.com/kumahq/kuma/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.10.0"},{"fixed":"2.11.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}},{"package":{"name":"github.com/kumahq/kuma/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.12.0"},{"fixed":"2.12.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}},{"package":{"name":"github.com/kumahq/kuma/v2","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.13.0"},{"fixed":"2.13.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}},{"package":{"name":"github.com/kumahq/kuma","ecosystem":"Go","purl":"pkg:golang/github.com/kumahq/kuma"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wvmp-6r4v-j6cv/GHSA-wvmp-6r4v-j6cv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"}]}