News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-32288
CVE
Medium
· CVSS 5.3
False Positivearchive/tar package is not used
in KrakenD’s request processing pipeline. This CVE does not affect KrakenD deployments.Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.
Component
Go standard library (archive/tar)
Disclosed
Apr 8, 2026
CVSS Score
5.3
archive/tar package performs unbounded memory allocation when parsing the sparse
map section of old-format GNU tar entries. A specially crafted tar archive with an
oversized sparse map can cause the parser to allocate an arbitrarily large amount of
memory, leading to denial of service.Stay up to date with KrakenD releases and important updates