News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-32280
CVE
Medium
· CVSS 5.3
Medium ImpactThis vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.
Component
Go standard library (crypto/x509)
Disclosed
Apr 8, 2026
CVSS Score
5.3
crypto/x509 package performs an unexpectedly large amount of work when building
certain certificate chains for validation. A specially crafted certificate or certificate
chain presented during a TLS handshake can cause the server to spend disproportionate CPU
time on chain construction, potentially leading to denial of service.Community Edition
2.13.4
addresses this advisory
Affected CE versions
>= 2.0, < 2.13.4
Enterprise Edition
2.13.2
addresses this advisory
Affected EE versions
>= 2.0, < 2.13.2
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates