Related Documentation
Made by
Kong Inc.
Supported Gateway Topologies
hybrid db-less traditional
Supported Konnect Deployments
hybrid cloud-gateways serverless
Compatible Protocols
grpc grpcs http https
Priority
810
Minimum Version
Kong Gateway - 3.11

3.16.0.0

Release date 2026/09/15

Feature

  • Added a ca_certificates config option. When set, call nodes verify the server’s TLS certificate against a trust store built solely from the referenced CA certificates instead of the global lua_ssl_trusted_certificate set. Ignored when a node’s ssl_verify is disabled.

  • Added support for reading the authenticated Kong Identity principal with the property node using kong.client.principal and nested fields such as kong.client.principal.metadata.rate_tier.

Bugfix

  • Fixed an issue where replaced response bodies kept stale upstream validators and representation metadata.

  • Fixed an issue where the response node set Content-Type: application/octet-stream for json_to_xml output. It now defaults to application/xml when no explicit Content-Type is provided.

  • Fixed an issue where the exit node sent a string body without a correct Content-Type. It now uses the content type that the source node declares, for example application/xml for json_to_xml output, and defaults to application/octet-stream in the request phase.

  • Fixed CVE-2026-14916 by binding the JWT algorithm to the verification key’s type in the jwt_verify node, so a symmetric algorithm can no longer be verified against an asymmetric key, preventing an authentication bypass where an attacker forges tokens by using the public key as an HMAC shared secret, under configurations where the node uses a PEM key string and allowed_algorithms is unset (any algorithm accepted).

  • Fixed the body handling of the exit and service_request nodes when the body input is a JSON null. The nodes sent the internal Lua value as the string “userdata: NULL”. The exit node now sends no body. The service_request node now keeps the upstream request body.

  • Added node source and runtime phase metadata to Datakit tracing events so Konnect Debugger can reconstruct the Datakit node graph from captured trace data.

  • Fixed an issue where several datakit instances (the base plugin plus clones) that ran in one request overwrote each other’s active-tracing capture. Each datakit instance now reports its own capture, keyed by its plugin id, and the capture payload carries the plugin_name field. Datakit plugin spans also carry a proxy.kong.plugin.ref attribute set to the base plugin name.

3.15.0.6

Release date 2026/09/16

Bugfix

  • Fixed an issue where the exit node sent a string body without a correct Content-Type. It now uses the content type that the source node declares, for example application/xml for json_to_xml output, and defaults to application/octet-stream in the request phase.

  • Fixed the body handling of the exit and service_request nodes when the body input is a JSON null. The nodes sent the internal Lua value as the string "userdata: NULL". The exit node now sends no body, and the service_request node now keeps the upstream request body.

3.15.0.5

Release date 2026/08/24

Bugfix

  • Fixed an issue where the response node set Content-Type: application/octet-stream for json_to_xml output. It now defaults to application/xml when no explicit Content-Type is provided.

3.15.0.3

Release date 2026/08/10

Bugfix

  • Security: Fixed CVE-2026-14916 by binding the JWT algorithm to the verification key’s type in the jwt_verify node. This means that a symmetric algorithm can no longer be verified against an asymmetric key, preventing an authentication bypass where an attacker forges tokens by using the public key as an HMAC shared secret, under configurations where the node uses a PEM key string and allowed_algorithms is unset (any algorithm accepted).

3.15.0.2

Release date 2026/07/21

Bugfix

  • Added node source and runtime phase metadata to Datakit tracing events so Konnect Debugger can reconstruct the Datakit node graph from captured trace data.

3.15.0.0

Release date 2026/07/02

Feature

  • Added a non_nil config attribute to the property node. When set to true, GET operations fail with an error if the property is unset, and SET operations fail with an error if the input is nil/null.

  • Added Konnect Debugger support for Datakit execution, including per-node spans, sanitized trace content capture with vault-aware redaction, and local debug trace responses using the same tracing event model with inline values.

Bugfix

  • Added Lua control plane compatibility checks to prevent unsupported Datakit configurations from being pushed to older data planes in hybrid mode.

3.14.0.15

Release date 2026/09/17

Bugfix

  • Fixed an issue where the exit node sent a string body without a correct Content-Type. It now uses the content type that the source node declares, for example application/xml for json_to_xml output, and defaults to application/octet-stream in the request phase.

  • Fixed the body handling of the exit and service_request nodes when the body input is a JSON null. The nodes sent the internal Lua value as the string "userdata: NULL". The exit node now sends no body, and the service_request node now keeps the upstream request body.

3.14.0.14

Release date 2026/08/26

Bugfix

  • Fixed an issue where the response node set Content-Type: application/octet-stream for json_to_xml output. It now defaults to application/xml when no explicit Content-Type is provided.

3.14.0.12

Release date 2026/08/10

Bugfix

  • Fixed CVE-2026-14916 by binding the JWT algorithm to the verification key’s type in the jwt_verify node, so a symmetric algorithm can no longer be verified against an asymmetric key. This prevents an authentication bypass where an attacker forges tokens by using the public key as an HMAC shared secret, under configurations where the node uses a PEM key string and allowed_algorithms is unset (any algorithm accepted).

3.14.0.8

Release date 2026/07/02

Bugfix

  • Fixed an issue where configuration parsing failed in packaged builds due to a missing jq parser file.

3.14.0.7

Release date 2026/06/23

Bugfix

  • Added Lua control plane compatibility checks to prevent unsupported Datakit configurations from being pushed to older data planes in hybrid mode.

3.14.0.0

Release date 2026/04/07

Feature

  • Added more implicit node outputs: * request.path * request.raw_path * request.port * request.method * request.scheme * request.version * service_response.status * service_response.raw_body * call.raw_body

  • Added JWT nodes: jwt_decode for decoding tokens without verification, jwt_verify for signature verification and claim validation using JWKS, and jwt_sign for creating and signing JWTs.

  • Consumer can now be set via property node.

  • the call node’s ssl_verify option to verify the TLS certificate when making HTTPS requests is now enabled by default.

Bugfix

  • Fixed type system bug to allow defining maps with string values for vault node.

  • Fixed an issue where datakit cache node instantiate proxy-cache-advanced redis module at config time causing dependency issue on Koko.

  • Fixed xml_to_json node to recognize text/xml content-type in addition to application/xml for XML request body processing, ensuring RFC 7303 compliance.

3.13.0.10

Release date 2026/08/20

Bugfix

  • Fixed an issue where the response node set Content-Type: application/octet-stream for json_to_xml output. It now defaults to application/xml when no explicit Content-Type is provided.

3.13.0.7

Release date 2026/06/30

Bugfix

  • Added Lua control plane compatibility checks to prevent unsupported Datakit configurations from being pushed to older data planes in hybrid mode.

3.13.0.1

Release date 2026/02/01

Bugfix

  • Fixed xml_to_json node to recognize text/xml content-type in addition to application/xml for XML request body processing, ensuring RFC 7303 compliance.

3.13.0.0

Release date 2025/12/18

Feature

  • Added json_to_xml node to support converting JSON or lua table to XML data.

  • Added xml_to_json node to support converting XML data to lua table and JSON format.

  • Added support for dynamic url in call node.

  • Added support for using the call node in the post-proxy phase.

  • Add support for using application/x-www-form-urlencoded as the body encoding.

  • added the ssl_verify flag to the call node. This flag allows users to control certificate verification when making HTTPS requests to the configured url endpoint. It cannot be disabled when the tls_certificate_verify global option is enabled.

  • Added support for clearing headers from the service_request and response nodes

Bugfix

  • Fixed implicit request node headers field to be correct type.

3.12.0.1

Release date 2025/11/18

Bugfix

  • Fixed implicit request node headers field to be correct type.

3.12.0.0

Release date 2025/10/01

Feature

  • Added caching support via a new cache node type.

  • Added support for conditional execution via the branch node.

  • Added vault support to the Datakit plugin. This unblocks common use cases such as storing secrets in Vault and retrieving them as tokens in Datakit.

Bugfix

  • Fixed plugin config validation to catch more invalid usage of the property node.

  • Fixed an issue where an invalid plugin instance could affect other plugins.

3.11.0.7

Release date 2026/02/26

Bugfix

  • Fixed plugin config validation to catch more invalid usage of the property node.

3.11.0.5

Release date 2025/10/23

Bugfix

  • Fixed implicit request node headers field to be correct type.

  • Fixed an issue where an invalid plugin instance could affect other plugins.

3.11.0.0

Release date 2025/07/03

Feature

  • Added new datakit plugin

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!