News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2025-68119 CVE High · CVSS 7.5 False Positive

cmd/go: VCS Toolchain Misinterpretation Enables Code Execution

This advisory does not affect KrakenD

This is a build-time vulnerability in the Go toolchain (cmd/go). KrakenD distributes pre-compiled binaries and does not invoke the Go toolchain at runtime. End users running KrakenD as a gateway are not affected.

Addressed through routine dependency maintenance in CE 2.12.1 and EE 2.12.3.

Component

Go standard library (cmd/go)

Disclosed

Jan 16, 2026

CVSS Score

7.5

Description

Go’s cmd/go command misinterprets version control system (VCS) repository metadata when resolving module paths. A specially constructed repository can cause go get or related toolchain commands to execute unintended code or write files outside the module cache, enabling supply-chain attacks against developer environments.

Stay up to date with KrakenD releases and important updates