News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-27143 CVE High · CVSS 7.5 False Positive

cmd/compile: Memory Corruption After Bound Check Elimination

This advisory does not affect KrakenD

This is a compile-time vulnerability in the Go compiler (cmd/compile). KrakenD distributes pre-compiled binaries and does not compile Go code at runtime. End users running KrakenD as a gateway are not affected by this issue.

Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.

Component

Go standard library (cmd/compile)

Disclosed

Apr 8, 2026

CVSS Score

7.5

Description

A memory corruption issue in Go’s cmd/compile compiler can occur following bound check elimination optimizations. Under specific code patterns, the compiler may eliminate a necessary array bounds check, producing a binary with potential out-of-bounds memory access at runtime.

Stay up to date with KrakenD releases and important updates