CVE-2025-58189
Medium
· CVSS 5.3
Medium ImpactThis CVE can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.
Component
Go standard library (crypto/tls)
Disclosed
Oct 8, 2025
CVSS Score
5.3
crypto/tls
package includes the client-supplied ALPN protocol list verbatim in the error
message without escaping. An attacker can inject arbitrary text into TLS error
logs by sending crafted ALPN values during the handshake. Fixed in Go 1.24.8
and Go 1.25.2.Community Edition
2.11.1
addresses this CVE
Affected CE versions
>= 2.0, < 2.11.1
Enterprise Edition
2.11.2
addresses this CVE
Affected EE versions
>= 2.0, < 2.11.2
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates