News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-27144 Medium · CVSS 5.3 False Positive

cmd/compile: No-op Interface Conversion Bypasses Overlap Checking

This CVE does not affect KrakenD

This is a compile-time vulnerability in the Go compiler (cmd/compile). KrakenD distributes pre-compiled binaries and does not compile Go code at runtime. End users running KrakenD as a gateway are not affected by this issue.

Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.

Component

Go standard library (cmd/compile)

Disclosed

Apr 8, 2026

CVSS Score

5.3

Description

Go’s cmd/compile compiler incorrectly handles certain no-op interface conversions during type assertion optimization, bypassing overlap checking. This can result in subtly incorrect code generation in rare circumstances involving interface type assertions.

Stay up to date with KrakenD releases and important updates