News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-3206 CVE Medium · CVSS 6.5 Medium Impact

backend/circuit-breaker: Uncontrolled Context Cancellation Causes Cascading Request Failures

Exploitable under specific conditions

This vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.

This CVE only affects deployments using KrakenD’s Circuit Breaker feature (backend/circuit-breaker in the configuration). Instances with no circuit breaker configured are not exposed to this vulnerability.

Component

Circuit Breaker

Disclosed

Feb 18, 2026

CVSS Score

6.5

Description

A vulnerability was identified in the Circuit Breaker component used by KrakenD. The vulnerability could lead to uncontrolled context cancellations, which can cascade through the system under load causing unexpected request failures and degraded service availability. Upgrading to CE 2.13.1 or EE 2.12.5 addresses the issue.

Version summary

Community Edition

2.13.1

addresses this advisory

Affected CE versions

>= 2.0, < 2.13.1

Enterprise Edition

2.12.5

addresses this advisory

Affected EE versions

>= 2.0, < 2.12.5

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates