News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2025-61726 Medium · CVSS 7.5 Medium Impact

net/http: Memory Exhaustion from Excessive Form Key-Value Pairs

Exploitable under specific conditions

This CVE can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.

KrakenD’s HTTP server is built on Go’s net/http and is exposed to this vulnerability when processing incoming requests. Deployments that receive form-encoded POST requests — or that have body transformation or validation plugins that trigger form parsing — are most exposed. Standard JSON API traffic is not affected.

Component

Go standard library (net/http)

Disclosed

Jan 16, 2026

CVSS Score

7.5

Description

Go’s net/http package does not limit the number of key-value pairs parsed from application/x-www-form-urlencoded request bodies. A client sending a request with an extremely large number of form fields can cause the server to consume unbounded memory while parsing the body, leading to denial of service.

Version summary

Community Edition

2.12.1

addresses this CVE

Affected CE versions

>= 2.0, < 2.12.1

Enterprise Edition

2.12.3

addresses this CVE

Affected EE versions

>= 2.0, < 2.12.3

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates