WHY GARTNER’S “CONTEXT MESH” CHANGES EVERYTHING AI CONNECTIVITY: THE ROAD AHEAD DON’T MISS API + AI SUMMIT 2026 SEPT 30 – OCT 1
  • Why Kong
    • Explore the unified API Platform
        • BUILD APIs
        • Kong Insomnia
        • API Design
        • API Mocking
        • API Testing and Debugging
        • MCP Client
        • RUN APIs
        • API Gateway
        • Context Mesh
        • AI Gateway
        • Event Gateway
        • Kubernetes Operator
        • Service Mesh
        • Ingress Controller
        • Runtime Management
        • DISCOVER APIs
        • Developer Portal
        • Service Catalog
        • MCP Registry
        • GOVERN APIs
        • Metering and Billing
        • APIOps and Automation
        • API Observability
        • Why Kong?
      • CLOUD
      • Cloud API Gateways
      • Need a self-hosted or hybrid option?
      • COMPARE
      • Considering AI Gateway alternatives?
      • Kong vs. Postman
      • Kong vs. MuleSoft
      • Kong vs. Apigee
      • Kong vs. IBM
      • GET STARTED
      • Sign Up for Kong Konnect
      • Documentation
      • FOR PLATFORM TEAMS
      • Developer Platform
      • Kubernetes and Microservices
      • Observability
      • Service Mesh Connectivity
      • Kafka Event Streaming
      • FOR EXECUTIVES
      • AI Connectivity
      • Open Banking
      • Legacy Migration
      • Platform Cost Reduction
      • Kafka Cost Optimization
      • API Monetization
      • AI Monetization
      • AI FinOps
      • FOR AI TEAMS
      • AI Governance
      • AI Security
      • AI Cost Control
      • Agentic Infrastructure
      • MCP Production
      • MCP Traffic Gateway
      • FOR DEVELOPERS
      • Mobile App API Development
      • GenAI App Development
      • API Gateway for Istio
      • Decentralized Load Balancing
      • BY INDUSTRY
      • Financial Services
      • Healthcare
      • Higher Education
      • Insurance
      • Manufacturing
      • Retail
      • Software & Technology
      • Transportation
      • See all Solutions
  • Pricing
      • DOCUMENTATION
      • Kong Konnect
      • Kong Gateway
      • Kong Mesh
      • Kong AI Gateway
      • Kong Event Gateway
      • Kong Insomnia
      • Plugin Hub
      • EXPLORE
      • Blog
      • Learning Center
      • eBooks
      • Reports
      • Demos
      • Customer Stories
      • Videos
      • EVENTS
      • API + AI Summit
      • Webinars
      • User Calls
      • Workshops
      • Meetups
      • See All Events
      • FOR DEVELOPERS
      • Get Started
      • Community
      • Certification
      • Training
      • COMPANY
      • About Us
      • We're Hiring!
      • Press Room
      • Contact Us
      • Kong Partner Program
      • Enterprise Support Portal
      • Documentation
  • Login
  • Book Demo
  • Get Started
Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. News
  4. Kong Security Update: Kong Is Not Affected by the PyPi-Distributed LiteLLM Supply Chain Attack
News
March 25, 2026
1 min read

Kong Security Update: Kong Is Not Affected by the PyPi-Distributed LiteLLM Supply Chain Attack

Kong

We want to ensure that our customers know that Kong is not affected by the PyPI LiteLLM incident publicized yesterday.

Kong does not rely on LiteLLM — whether PyPI-distributed or otherwise — for any components in our runtime stack. 

As you may know, a supply chain vulnerability affecting LiteLLM version 1.82.8, a popular open-source AI proxy library, was publicized yesterday. The malicious package, distributed via PyPI, executed a credential-stealing script capable of exfiltrating environment variables, cloud credentials, SSH keys, and other secrets from any environment where it was installed. 

Kong did not incorporate or use the LiteLLM library in its products.

If your organization uses LiteLLM independently — in development environments, CI/CD pipelines, or alongside other tooling — we'd encourage you to review the original GitHub disclosure and treat any environment that ran pip install litellm==1.82.8 as potentially compromised. 

Also, per the coverage by Comet, it is worthwhile to note that several other popular projects and agent frameworks rely on LiteLLM, including CrewAI, Browser-use, Opik, Mem0, DSPy, Agno, Guardrails, and Camel-AI. According to Comet, “Anyone who ran pip install or pip install --upgrade on any of these packages during the approximately 4-hour exposure window (roughly 09:00–13:30 UTC on March 24) could have pulled the compromised litellm as a transitive dependency.” We recommend referencing this blog if you want more information. 

If you have questions about Kong's security posture or would like to talk through your AI infrastructure architecture, reach out to your Kong account team or contact security@konghq.com.

—The Kong Security Team

More on this topic

eBooks

AI Governance Framework: Shadow AI Discovery & LLM Guardrails

Reports

Gartner® | How to Enable Agentic AI via API-Based Integration

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Kong

Recommended posts

Gartner Recognizes Kong as a Progressive AI Adopter

NewsMarch 20, 2026

For product teams, the long days of lengthy Product Requirements Documents (PRDs) and rigid documentation workflows are giving way to something faster and more dynamic. They’re now using AI to generate prototypes, validate concepts with virtual cust

Heather Halenbeck

Kong Insomnia Named in Gartner’s Market Guide for API and MCP Testing Tools

NewsMarch 4, 2026

The Gartner report profiles Kong’s Insomnia as “an API development platform that promotes collaboration during development and testing,” a recognition that reflects our commitment to give development teams of any size a purpose-built environment for

Haley Giuliano

Kong Wins AI Innovator of the Year for Pioneering AI Connectivity

NewsMarch 2, 2026

SiliconANGLE Media runs this annual awards program to recognize companies, technologies, and people moving the needle in B2B tech. Winners go through a review process by industry analysts and experts. Kong was recognized as the 2026 AI Innovator

Eric Pulsifer

From Pixels to APIs: The Programmable Economy is the Agentic Economy

NewsFebruary 27, 2026

The APIs that have been powering websites and apps created a massive market, but there are only up to 8 billion humans consuming them behind pixels. As LLMs are taking over the world — in the form of productized agents first — there will be 100X m

Augusto Marietti

Announcing Solace as Kong’s Newest Premium Technology Partner

NewsFebruary 10, 2026

Kong is excited to announce Solace as the newest member of our Premium Technology Partner Program, a program designed to deliver high-quality, reliable integrations that provide real business value for customers. Together, Kong and Solace unify AP

Cindy Maurice

The 2025 Kong Year in Review

NewsDecember 30, 2025

With major advances in building the AI connectivity layer and soaring enterprise adoption of agentic systems, this year sparked a hockey-stick surge in demand for the infrastructure that powers intelligent agents.  Below is a rundown on the updates,

Amit Dey

The Age of AI Connectivity

NewsDecember 18, 2025

A decade ago, we set out to connect the world through APIs, which we saw as fundamental building blocks of software. Before Kong, we founded Mashape as the first API marketplace to provide an assembly line for developers building apps, and then we o

Augusto Marietti

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Ask AI for a summary of Kong
Stay connected
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
    • Legal
    • Terms
    • Privacy
    • Trust and Compliance
    • Platform
    • Kong AI Gateway
    • Kong Konnect
    • Kong Gateway
    • Kong Event Gateway
    • Kong Insomnia
    • Documentation
    • Book Demo
    • Compare
    • AI Gateway Alternatives
    • Kong vs Apigee
    • Kong vs IBM
    • Kong vs Postman
    • Kong vs Mulesoft
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Apigee
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community

Increase developer productivity, security, and performance at scale with the unified platform for API management and AI.

  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
© Kong Inc. 2026