— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Kong.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 329,
"average_time_to_first_program_response": 17,
"average_time_to_report_resolved": 2009,
"handle": "kong",
"id": 0,
"managed_program": true,
"name": "Kong",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 84,
"submission_state": "open",
"url": "https://hackerone.com/kong",
"website": "http://konghq.com",
"targets": {
"in_scope": [
{
"asset_identifier": "GitHub Actions in our Public Repositories ",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Our security program covers GitHub Actions on a case-by-case basis. We don't maintain a comprehensive list of in-scope repositories as relevance varies.\nWhen reporting GitHub Actions vulnerabilities, please provide context about:\nThe action's function and permissions\nWhat sensitive data it processes\nIts connection to production environments\nWhether it's maintained by our organization\nWe'll evaluate each submission individually based on security impact and relevance to our infrastructure.",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "Insomnia CLI (inso)",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "inso is the official Insomnia Command Line Interface (CLI) tool, designed to support automation, CI/CD integration, and advanced API workflows. It enables developers to lint API specs, run tests, and generate configuration artifacts such as Kong declarative configs from Insomnia project files. The CLI interfaces directly with exported Insomnia data and is intended for headless, scriptable operations.\nKey Technologies: Node.js CLI, YAML/JSON processing\nInstallation: Available via npm (npm install -g insomnia-inso)\nDocumentation: https://docs.insomnia.rest/inso-cli/introduction",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Insomnia Desktop Client",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The Insomnia Desktop Client is a cross-platform REST, GraphQL, and gRPC client used for designing, debugging, and testing APIs. Built using Electron, it allows users to send requests, inspect responses, manage environments, organize requests into collections, and generate API documentation. The client supports plugin extensions and sync capabilities through user accounts, which interact with Kong's backend services. It is available on Windows, macOS, and Linux.\nKey Technologies: Electron, React, Node.js\n\nDownload Locations: https://insomnia.rest/download",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Kong Gateway Enterprise",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Kong Gateway OSS",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": null,
"integrity_requirement": null,
"max_severity": "medium"
},
{
"asset_identifier": "Kong Gateway Plugins (Kong-Supported Only)",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Kong Gateway Plugins extend the core functionality of Kong Gateway by providing modular support for authentication, traffic control, logging, transformation, observability, and security features. This asset includes only the officially supported Kong Plugins as listed on Kong Hub under the “Kong Supported” category.\nThese plugins are maintained and supported by Kong Inc. and are subject to enterprise-grade SLAs and compatibility guarantees. They are used in both OSS and Enterprise deployments (with some plugins being Enterprise-only) and may operate at various phases of the request/response lifecycle.\nKey Capabilities of Kong-Supported Plugins:\nAuthentication & Security:\nKey Authentication, JWT, OAuth 2.0, OIDC, Mutual TLS\nIP Restriction, ACL, Bot Detection, CORS\nTraffic Control & Transformation:\nRate Limiting, Request/Response Transformer, URL Rewriting\nRequest Termination, Forward Proxy, Traffic Splitting\nLogging & Observability:\nHTTP Log, Syslog, TCP/UDP Log, Prometheus, Datadog, StatsD\nAnalytics & Monitoring:\nVitals (Enterprise), Zipkin, OpenTelemetry, Correlation ID\nEnterprise-Only Features:\nLDAP Auth, Vault Secrets, RBAC enforcement plugins, Upstream mTLS\nDeveloper Experience Enhancements:\nRequest Validator, gRPC Transcoding, GraphQL Rate Limiting\nSupported Environments:\nCompatible with Kong Gateway OSS and Enterprise (some plugins Enterprise-only)\nKubernetes, VMs, Docker, and Hybrid mode deployments\n📖 Plugin Directory (Kong-Supported Only):\n\nhttps://docs.konghq.com/hub/?category=Kong%20Supported",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Kong Mesh",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Kong Mesh is an enterprise-grade service mesh built on top of Kuma, designed to provide secure, observable, and resilient service-to-service communication across modern, distributed environments. It enables zero-trust architectures, advanced traffic control, and full-service connectivity across Kubernetes, virtual machines, hybrid cloud, and multi-cloud infrastructure.\nKong Mesh includes powerful enterprise capabilities such as multi-zone support, fine-grained traffic policies, RBAC, audit logging, and native integrations with Kong Gateway for ingress and egress management. It uses Envoy as the sidecar proxy to enforce mesh policies and collect observability data.\nKey Capabilities:\nZero-trust security with automatic mTLS and traffic permissions\nFine-grained traffic policies (routing, retries, timeouts, circuit breaking)\nFull observability (metrics, logs, tracing via Envoy)\nMulti-zone and multi-cluster mesh deployments\nDeclarative configuration with CRDs (Kubernetes) or HTTP API (Universal)\nRole-Based Access Control (RBAC) and audit logging\nNative support for Kubernetes, VMs, hybrid, and multi-cloud\nIntegration with Kong Gateway for seamless ingress/egress control\nSupported Environments:\nKubernetes (all major distributions)\nUniversal mode (VMs and bare metal)\nHybrid and multi-cloud infrastructure\n📄 Supported Versions:\n\nKong Mesh Compatibility Chart\n📖 Installation Documentation:\n\nhttps://docs.konghq.com/mesh/latest/install/",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Subdomain Takeover - konghq.com",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": "medium",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Subdomain takeover vulnerabilities on Kong's domain infrastructure (\\*.konghq.com). This includes documentation sites, API endpoints, marketing pages, developer portals, and service integrations. Successful takeovers can enable phishing attacks, credential harvesting, session hijacking, and brand impersonation due to user trust in Kong's domain.\n\nCommon attack vectors include abandoned cloud services (S3, GitHub Pages, Netlify), expired third-party integrations (Heroku, Vercel), and legacy CNAME records pointing to decommissioned services.\n\n* * *\n\n## Instructions to Researcher\n\n\\**SUBDOMAIN TAKEOVER - *.konghq.com ONLY**\n\n**Requirements:** Must successfully control the subdomain (not just dangling DNS), demonstrate Medium+ impact, and provide complete evidence package.\n\n**In-Scope:** Successful takeovers allowing malicious content hosting, phishing/credential harvesting potential, or cookie/session security impact.\n\n**Out of Scope:** Dangling DNS without takeover proof, low impact findings, and non-Kong domains.\n\n**Required Evidence:**\n\n1. **Technical:** Subdomain URL, service type, takeover method\n2. **Proof:** Screenshots of your content on Kong subdomain\n3. **Impact:** Why this matters (phishing risk, user exposure, etc.)\n4. **Steps:** How to reproduce\n\n**Auto-Reject If Missing:** Proof of successful takeover, impact justification, or complete reproduction steps.\n\nLow impact findings are NOT eligible for bounty.",
"integrity_requirement": "medium",
"max_severity": "high"
},
{
"asset_identifier": "developer.konghq.com",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This is a static documentation site for the Kong developer ecosystem. It does **not** include authentication, private data, or customer records. However, it is a high-visibility property used by prospects, customers, and partners.\n\nYou may test for:\n\n* Content injection or defacement\n \n* Directory traversal\n \n* Access to unpublished content or hidden routes\n \n* Misconfigured Netlify settings (e.g., edge redirects, branch deploys)\n \n* JavaScript-based DOM manipulation or client-side XSS\n \n\n**Do not test:**\n\n* Login or authentication flows (none exist)\n \n* Rate limiting or brute force behavior\n \n* API fuzzing (no API backend is served directly)\n \n\nAll testing should be non-destructive and limited to publicly accessible pages.",
"integrity_requirement": "medium",
"max_severity": "high"
},
{
"asset_identifier": "http://cloud.konghq.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Kong Konnect is a unified SaaS control plane that allows organizations to manage their API Gateway, Service Mesh, and Ingress Controller deployments globally. The `cloud.konghq.com` application serves as the central command center where users configure services, routes, plugins, and consumer policies.\n\nWe invite security researchers to help us protect the integrity of this management console. We are specifically looking for vulnerabilities that could allow unauthorized access to tenant configurations, privilege escalation within an organization, or leakage of sensitive API tokens and credentials.\n\n## **Target Information**\n\n### **Primary Scope**\n| Asset | Type | Description |\n| :--- | :--- | :--- |\n| **`cloud.konghq.com`** | Web Application | The core management console for Kong Konnect. This includes the dashboard, Gateway Manager, Mesh Manager, and Service Hub interfaces. |\n| **`*.api.konghq.com`** | API Endpoint | The backend API endpoints backing the Konnect web console (used by the UI and CLI). |\n\n## **Out of Scope & Exclusions**\nThe following assets and behaviors are strictly **out of scope**. Testing these may result in immediate disqualification.\n\n* **Customer Data Planes:** `*.edge.gateways.konghq.com`, `*.kongcloud.io`, or any domain representing a customer's specific proxy instance. These are production traffic nodes; attacking them affects our customers' live API traffic.\n* **Marketing & Docs:** `konghq.com` (marketing site), `docs.konghq.com`, and `support.konghq.com`.\n* **Denial of Service (DoS):** Any testing that degrades the performance of the control plane or data planes.\n* **Social Engineering:** Phishing employees, support staff, or other customers.\n\n## **Focus Areas & Vulnerability Categories**\nWe are particularly interested in critical vulnerabilities that compromise the multi-tenant nature of the platform.\n\n### **1. Multi-Tenancy & Authorization (Highest Priority)**\n* **Cross-Tenant Access:** Ability to view, modify, or delete configurations (Services, Routes, Plugins) belonging to another organization.\n* **IDOR (Insecure Direct Object References):** Accessing objects (e.g., `consumers`, `certificates`, `runtime_groups`) by manipulating IDs in API calls.\n* **Privilege Escalation:** Vertical escalation from a \"Read-Only\" role to an \"Admin\" role within a Konnect Organization.\n\n### **2. Identity & Session Management**\n* **Authentication Bypasses:** Circumventing SSO (SAML/OIDC) or MFA enforcement.\n* **OAuth/OIDC Flaws:** Improper handling of `state` parameters, redirect URIs, or token leakage in the `us.identity.konghq.com` flow.\n\n### **3. Injection & Input Validation**\n* **Stored XSS:** Particularly in fields that are rendered in the Developer Portal or shared across team members (e.g., Service descriptions, Plugin configuration fields).\n* **Command Injection:** Attempting to inject shell commands via configuration inputs (though unlikely given the architecture, this is critical if found).\n* **SSRF (Server-Side Request Forgery):** Triggering backend requests to internal Kong infrastructure or metadata services via webhooks or alert notification configurations.\n\n### **4. Sensitive Data Exposure**\n* **Credential Leakage:** Leaking `Client Secrets`, `API Keys`, or `RBAC Tokens` in API responses or frontend JavaScript bundles.\n* **PII Exposure:** Unauthorized access to user emails or profile data of user in different organizations. (Users profile data within the same organization is accessible by design. )\n\n## **Qualifying Vulnerabilities**\n* Remote Code Execution (RCE)\n* SQL Injection\n* Broken Access Control (IDOR, Cross-Tenant)\n* Server-Side Request Forgery (SSRF)\n* Cross-Site Scripting (XSS) (Stored/Reflected with clear impact)\n* Cross-Site Request Forgery (CSRF) on state-changing actions\n* Subdomain Takeovers (on in-scope domains only)\n\n## **Non-Qualifying Issues**\n* Cookie / Authorization Bearer replacement.\n* Clickjacking on pages with no sensitive actions.\n* Reflected XSS that requires unlikely user interaction (e.g., self-XSS).\n* Missing security headers (CSP, HSTS) without a proof of concept of exploitability.\n* Logout CSRF.\n* Information disclosure of non-sensitive public data (e.g., version numbers).\n* Rate limiting issues (unless they lead to severe resource exhaustion).\n\n\n\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://*.api.konghq.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The Kong Konnect API is a set of RESTful APIs used to programmatically interact with Kong Konnect's SaaS control plane. These endpoints enable users to automate and manage API gateway configurations, service mesh entities, developer portals, teams, and API products. The Konnect API is used by integrators, platform teams, and developers to extend Konnect capabilities without relying on the web UI.\nKonnect API endpoints are hosted across multiple regional domains. Each region has a dedicated API domain, and some features (such as authentication or control plane registration) use global endpoints. Authentication is handled using personal access tokens or service accounts.\nGlobal API Endpoint:\nhttps://global.api.konghq.com\nUsed for authentication and operations related to global entities like organizations, identity providers, and licensing.\nRegional API Endpoints:\n\nThese endpoints are used to manage regional entities such as services, routes, plugins, control planes, and Dev Portals. They are tied to the region where your Konnect control plane is deployed:\nhttps://us.api.konghq.com – United States\nhttps://eu.api.konghq.com – European Union\nhttps://au.api.konghq.com – Australia\nhttps://in.api.konghq.com – India\nhttps://me.api.konghq.com – Middle East\nSupported Capabilities via API:\nRegister and configure Gateway and Mesh control planes\nManage services, routes, upstreams, certificates, and plugins\nProvision and manage Dev Portals and teams\nDefine and publish API products\nRetrieve analytics and telemetry (region-dependent)\nManage authentication, tokens, and service accounts\n📖 Konnect API Documentation:\n\nhttps://docs.konghq.com/konnect/api/\n📖 Network Architecture & Endpoint Reference:\n\nhttps://docs.konghq.com/konnect/network/",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://app.insomnia.rest/",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://app.insomnia.rest/ is the web-based platform for managing user accounts, API project sync, and collaboration features within Insomnia. It provides authenticated access to synced workspaces, team collaboration tools, and account management functions. The web application integrates with the Insomnia Desktop Client to enable encrypted data synchronization across devices using Kong's backend infrastructure. Users can view and manage shared collections, team invites, and workspace history from the web interface.\nKey Features:\nWorkspace and request sync\nTeam and project collaboration\nEncrypted data at rest and in transit\nAccount and organization management\nKey Technologies: React, Node.js, GraphQL, Auth0 (authentication)\nAccess URL: https://app.insomnia.rest/",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "https://us.identity.konghq.com/*",
"asset_type": "WILDCARD",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Kong Identity is the authentication and identity management service for Kong Konnect. \nThis service provides OAuth 2.0 and OpenID Connect (OIDC) compliant endpoints for token \nissuance, introspection, and user claims retrieval.\n\nIn Scope Testing Areas:\n- Public endpoints under https://us.identity.konghq.com/auth/ including:\n - /authorize\n - /.well-known/jwks\n - /.well-known/openid-configuration\n - /introspect\n - /userinfo\n- Authentication or authorization bypasses\n- Token handling and validation issues (JWT/JWKS)\n- OIDC/OAuth2 flow misconfigurations affecting Konnect\n\nOut of Scope:\n- Denial-of-service or volumetric attacks\n- Social engineering or phishing\n- Testing on non-production or staging environments\n- Any activity requiring non-bug-bounty credentials\n\n📖 Reference Documentation:\n- https://developer.konghq.com/kong-identity/\n- https://developer.konghq.com/api/konnect/kong-identity/v1/",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "konghq.com",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "low",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Description:\nThis domain hosts Kong’s primary marketing site, built with Next.js and backed by a headless CMS. It includes content for prospective customers, product landing pages, documentation links, customer forms, and search features. While no customer or employee data is stored on this site, its visibility and business value justify inclusion in the bounty program.\n\nThe underlying architecture is based on a monorepo structure using Turborepo, with separate services for the website, content management, design system, and search indexing. This is a production system served to global audiences.\n\nInstruction\nThis is Kong’s public marketing site. Testing should focus on public content and unauthenticated access paths.\n\nYou may test for:\n\nDOM-based or reflected XSS\n\nContent spoofing or injection\n\nHTML/JS/CSS manipulation\n\nSEO abuse or URL-based issues (e.g., open redirect, clickjacking)\n\nExposure of unpublished content or previews\n\nNetlify or CDN misconfigurations\n\nJavaScript security issues or client-side logic flaws\n\nDo not test:\n\nAuthenticated CMS administration endpoints (e.g., Payload admin dashboard)\n\nCustomer or internal partner login flows (none exist on this domain)\n\nRate-limiting or brute-force protections\n\nSocial engineering or phishing scenarios\n\nThis site is eligible for bounties, but scope is limited to vulnerabilities that affect integrity or availability of the public experience or expose unpublished content",
"integrity_requirement": "medium",
"max_severity": "high"
}
],
"out_of_scope": [
{
"asset_identifier": "*.*.edge.gateways.konghq.com",
"asset_type": "WILDCARD",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The above domains are used for hosting customer-specific Dedicated Cloud Gateway deployments as part of Kong Konnect’s managed Gateway Manager offering. These environments represent isolated data plane nodes that are fully managed by Kong but deployed per customer, operating outside of Kong’s shared multi-tenant SaaS infrastructure. These gateways do not include shared backend logic, centralized user interfaces, or control plane components used by the broader Kong Konnect platform. Security testing against these customer-owned gateways may interfere with production traffic and is not authorized under this program. \n**Reason for Descoping:**\n\n* Domains host customer-specific data plane nodes provisioned via Konnect’s Dedicated Cloud Gateway service\n \n* No shared backend logic or centralized SaaS infrastructure\n \n* Testing could impact customer production environments and violate service agreements \n **Out of Scope URLs:** \n 🌐 `*.gateways.konghq.com` \n 🌐 `*.edge.gateways.konghq.com` \n 🌐 `*.gateways.konggateway.com` \n 🌐 `*.edge.gateways.konggateway.com`\n \n\nFor reference: [Dedicated Cloud Gateways Overview](https://docs.konghq.com/konnect/gateway-manager/dedicated-cloud-gateways/)",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "*.gateways.konghq.com",
"asset_type": "WILDCARD",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The above domains are used for hosting customer-specific Dedicated Cloud Gateway deployments as part of Kong Konnect’s managed Gateway Manager offering. These environments represent isolated data plane nodes that are fully managed by Kong but deployed per customer, operating outside of Kong’s shared multi-tenant SaaS infrastructure. These gateways do not include shared backend logic, centralized user interfaces, or control plane components used by the broader Kong Konnect platform. Security testing against these customer-owned gateways may interfere with production traffic and is not authorized under this program. \n**Reason for Descoping:**\n\n* Domains host customer-specific data plane nodes provisioned via Konnect’s Dedicated Cloud Gateway service\n \n* No shared backend logic or centralized SaaS infrastructure\n \n* Testing could impact customer production environments and violate service agreements \n **Out of Scope URLs:** \n 🌐 `*.gateways.konghq.com` \n 🌐 `*.edge.gateways.konghq.com` \n 🌐 `*.gateways.konggateway.com` \n 🌐 `*.edge.gateways.konggateway.com`\n \n\nFor reference: [Dedicated Cloud Gateways Overview](https://docs.konghq.com/konnect/gateway-manager/dedicated-cloud-gateways/)",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "Kong Enterprise Gateway - Sandbox Functionality",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "Non-Kong GitHub Repositories",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Any GitHub repository that is not under an official Kong organization (e.g., github.com/Kong) or explicitly listed as in-scope is considered out of scope.\nExamples of Non-Kong Repositories:\nPersonal repositories of current or former employees\nForks or mirrors of Kong repositories outside official organizations\nRepositories belonging to third-party vendors, partners, or integrations\nAny repositories under GitHub organizations not owned or maintained by Kong\nReason for Exclusion:\n\nThese repositories are not maintained or governed by Kong and may not reflect our production environments, policies, or codebases.",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "Non-Kong Plugins",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Non-Kong Plugins listed on the Kong Hub at https://docs.konghq.com/hub/ are third-party or community-maintained extensions for Kong Gateway. These plugins are not developed, maintained, or supported by Kong Inc., and may follow their own security practices, versioning, and update cycles. As such, they are out of scope for this program.\nReason for Descoping:\nDeveloped and maintained by third-party contributors\nNot supported or reviewed under Kong’s internal security processes\nSecurity issues should be reported directly to the plugin maintainer",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://*.konghq.tech",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Konnect Development Environment\nIncludes:\nhttps://cloud.konghq.tech (Konnect Development Site)\nhttps://us.api.konghq.tech (Konnect Development API)\nDescription:\n\nThe Konnect Development Environment consists of internal, non-production systems used by Kong Inc. engineering teams for development and testing of Kong Konnect features. These systems may include experimental code, unstable configurations, and test data. They are not intended for public access or security research and are therefore explicitly out of scope for this program.\nReason for Descoping:\nInternal-only environments\nNot subject to production security controls\nMay expose non-finalized or debug-level functionality\nOut of Scope URLs:\n\n🌐 https://cloud.konghq.tech\n\n🌐 https://us.api.konghq.tech",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://docs.konghq.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Kong documentation website at https://docs.konghq.com/ hosts the official product documentation for Kong Gateway, Kong Konnect, Kong Mesh, and related tools. It provides user guides, configuration references, tutorials, and release notes to assist customers and the community. This site serves static and informational content only and does not process sensitive user data, perform dynamic backend operations, or directly integrate with Kong’s production environments. Therefore, it is out of scope for security testing.\n\nReason for Descoping:\n\nStatic and informational documentation content\n\nNo backend application logic tied to Kong Konnect, Kong Gateway, or production services\n\nMaintained separately from core SaaS, product, and operational infrastructure\n\nOut of Scope URL: 🌐 https://docs.konghq.com/",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://httpbin.konghq.com/",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The `https://httpbin.konghq.com/` domain hosts a public instance of [httpbin](https://httpbin.org), an open-source HTTP request and response testing tool, deployed by Kong to support API demonstrations, testing, and tutorials. It is not part of Kong’s production infrastructure, does not contain proprietary application logic, and does not handle sensitive customer data. This instance is periodically reset, unauthenticated, and operates in a sandboxed environment. \n**Reason for Descoping:**\n\n* Used solely for demonstration and API testing purposes\n \n* Runs open-source, stateless software without Kong-specific enhancements\n \n* Does not process or store customer data\n \n* Not part of Kong’s production infrastructure or supported products \n **Out of Scope URL:** \n 🌐 `https://httpbin.konghq.com/`",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "https://insomnia.rest/",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Insomnia marketing site at https://insomnia.rest/ is a public-facing, informational website used to promote Insomnia’s API client products. It includes product overviews, feature highlights, documentation links, and download pages. This site does not contain sensitive user data or interact with production services and is therefore out of scope for security testing.\n\nReason for Descoping:\nStatic marketing and informational content\nNo connection to core Insomnia application infrastructure\nNo authentication, sensitive data processing, or business logic\n\nOut of Scope URL:\n\n🌐 https://insomnia.rest/",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://kuma.io/",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The Kuma website at https://kuma.io/ serves as the marketing and informational site for Kuma, the open-source service mesh project maintained by Kong Inc. It offers documentation, product overviews, community resources, and blog content. This site does not contain sensitive user data or integrate with production infrastructure and is therefore out of scope for security testing.\nReason for Descoping:\nInformational and static marketing content\nNo backend application logic tied to Kong Konnect or Kong Gateway\nMaintained independently from core SaaS and product infrastructure\nOut of Scope URL:\n\n🌐 https://kuma.io/",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}GitHub Actions in our Public Repositories· noneInsomnia CLI (inso)· criticalInsomnia Desktop Client· criticalKong Gateway Enterprise· criticalKong Gateway OSS· mediumKong Gateway Plugins (Kong-Supported Only)· criticalKong Mesh· criticalSubdomain Takeover - konghq.com· high*.*.edge.gateways.konghq.com*.gateways.konghq.com*.konghq.techKong Enterprise Gateway - Sandbox FunctionalityNon-Kong GitHub RepositoriesNon-Kong Plugins