News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-25679 CVE Medium · CVSS 5.3 Medium Impact

net/url: IPv6 Literal Validation Bypass

Exploitable under specific conditions

This vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.

KrakenD uses net/url to parse and validate backend URLs. A crafted IPv6 hostname in a proxied request could bypass host validation, potentially reaching unintended network targets. Any deployment that accepts dynamic upstream URL components from external sources is most exposed.

Component

Go standard library (net/url)

Disclosed

Mar 9, 2026

CVSS Score

5.3

Description

Go’s net/url package incorrectly accepts IPv6 literal addresses that do not appear at the start of the host portion of a URL, violating RFC 3986. This validation gap could allow a specially crafted URL to reach unintended network targets or circumvent host-based access controls in applications that rely on net/url for URL parsing and validation.

Version summary

Community Edition

2.13.2

addresses this advisory

Affected CE versions

>= 2.0, < 2.13.2

Enterprise Edition

2.13.0

addresses this advisory

Affected EE versions

>= 2.0, < 2.13.0

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates