Release date 2026/09/15
Feature
Added a
ca_certificatesconfig option. When set,callnodes verify the server’s TLS certificate against a trust store built solely from the referenced CA certificates instead of the globallua_ssl_trusted_certificateset. Ignored when a node’sssl_verifyis disabled.Added support for reading the authenticated Kong Identity principal with the
propertynode usingkong.client.principaland nested fields such askong.client.principal.metadata.rate_tier.
Bugfix
Fixed an issue where replaced response bodies kept stale upstream validators and representation metadata.
Fixed an issue where the
responsenode setContent-Type: application/octet-streamforjson_to_xmloutput. It now defaults toapplication/xmlwhen no explicitContent-Typeis provided.Fixed an issue where the
exitnode sent a string body without a correctContent-Type. It now uses the content type that the source node declares, for exampleapplication/xmlforjson_to_xmloutput, and defaults toapplication/octet-streamin the request phase.Fixed CVE-2026-14916 by binding the JWT algorithm to the verification key’s type in the
jwt_verifynode, so a symmetric algorithm can no longer be verified against an asymmetric key, preventing an authentication bypass where an attacker forges tokens by using the public key as an HMAC shared secret, under configurations where the node uses a PEM key string andallowed_algorithmsis unset (any algorithm accepted).Fixed the body handling of the
exitandservice_requestnodes when the body input is a JSON null. The nodes sent the internal Lua value as the string “userdata: NULL”. Theexitnode now sends no body. Theservice_requestnode now keeps the upstream request body.Added node source and runtime phase metadata to Datakit tracing events so Konnect Debugger can reconstruct the Datakit node graph from captured trace data.
Fixed an issue where several datakit instances (the base plugin plus clones) that ran in one request overwrote each other’s active-tracing capture. Each datakit instance now reports its own capture, keyed by its plugin id, and the capture payload carries the
plugin_namefield. Datakit plugin spans also carry aproxy.kong.plugin.refattribute set to the base plugin name.