News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-32288 Medium · CVSS 5.3 False Positive

archive/tar: Unbounded Memory Allocation in GNU Sparse Map Parsing

This CVE does not affect KrakenD

KrakenD does not parse tar archives at runtime. The archive/tar package is not used in KrakenD’s request processing pipeline. This CVE does not affect KrakenD deployments.

Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.

Component

Go standard library (archive/tar)

Disclosed

Apr 8, 2026

CVSS Score

5.3

Description

Go’s archive/tar package performs unbounded memory allocation when parsing the sparse map section of old-format GNU tar entries. A specially crafted tar archive with an oversized sparse map can cause the parser to allocate an arbitrarily large amount of memory, leading to denial of service.

Stay up to date with KrakenD releases and important updates