CVE-2025-61732
Medium
· CVSS 6.3
False PositiveAddressed through routine dependency maintenance in CE 2.13.0 and EE 2.12.4.
Component
Go standard library (cmd/cgo)
Disclosed
Feb 10, 2026
CVSS Score
6.3
/* ... */) allowed an
attacker to craft a Go source file that embeds arbitrary C code into the resulting cgo
binary. The injected C code would not be visible when reading the Go source but would
be compiled and executed as part of the final binary, enabling supply-chain attacks
against projects that accept external Go source contributions.Stay up to date with KrakenD releases and important updates