News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-32281 CVE Medium · CVSS 5.3 Medium Impact

crypto/x509: Inefficient Policy Validation

Exploitable under specific conditions

This vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.

KrakenD validates X.509 certificates during TLS handshakes. Deployments with mutual TLS (mTLS) configured — where KrakenD validates client certificates — are most exposed, as a client can present a crafted certificate chain. Deployments using only server-side TLS are at lower risk.

Component

Go standard library (crypto/x509)

Disclosed

Apr 8, 2026

CVSS Score

5.3

Description

Go’s crypto/x509 certificate policy validation algorithm has poor time complexity when processing specially crafted policy constraint structures within X.509 certificates. An attacker able to present such a certificate chain during a TLS handshake can cause the server to expend excessive CPU resources during policy graph traversal, potentially leading to denial of service.

Version summary

Community Edition

2.13.4

addresses this advisory

Affected CE versions

>= 2.0, < 2.13.4

Enterprise Edition

2.13.2

addresses this advisory

Affected EE versions

>= 2.0, < 2.13.2

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates