News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2025-68121 CVE Medium · CVSS 5.9 Medium Impact

crypto/tls: TLS Session Key Mismanagement in Config.Clone and GetConfigForClient

Exploitable under specific conditions

This vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.

The Config.Clone variant can affect any deployment that clones its TLS configuration at startup, which may occur in multi-listener setups. The GetConfigForClient variant only affects deployments using a custom per-client TLS callback. Upgrading is recommended regardless of configuration.

Component

Go standard library (crypto/tls)

Disclosed

Feb 10, 2026

CVSS Score

5.9

Description

Two related flaws in Go’s crypto/tls package affect session ticket key handling:

  • tls.Config.Clone leaks session ticket keys and ignores full certificate chain expiration when the original Config has custom session ticket keys set.
  • tls.Config.GetConfigForClient does not correctly propagate session ticket keys to the returned Config when authentication parameters are modified.

Both issues can result in authentication state inconsistency or unintended session ticket exposure.

Version summary

Community Edition

2.13.0

addresses this advisory

Affected CE versions

>= 2.0, < 2.13.0

Enterprise Edition

2.12.4

addresses this advisory

Affected EE versions

>= 2.0, < 2.12.4

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates