Kong Responsible Vulnerability Disclosure

We take cybersecurity seriously and value the contributions of the security community at large. The responsible disclosure of potential issues helps us ensure the security and privacy of our customers and data.

Reporting a Vulnerability

If you believe you've found a security issue in one of our products or services, please send it to us at vulnerability@konghq.com and include the following details with your report:

  • A description of the issue and where it is located
  • Steps required to reproduce the issue
  • Potential impact of the vulnerability

Bug Bounty Program

Kong maintains a private, invite-only bug bounty program through HackerOne. If you are interested in joining our bug bounty program, please email vulnerability@konghq.com.

Thank you for helping us keep Kong customers and data safe.