News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-32289 CVE Medium · CVSS 5.3 False Positive

html/template: JS Template Literal Context Incorrectly Tracked

This advisory does not affect KrakenD

KrakenD is an API gateway and does not use Go’s html/template package to generate HTML or JavaScript responses. The vulnerable code path in html/template is never invoked during normal KrakenD operation.

Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.

Component

Go standard library (html/template)

Disclosed

Apr 8, 2026

CVSS Score

5.3

Description

Go’s html/template package incorrectly tracks JavaScript template literal context in certain template patterns. Content that appears after a template action inside a JS template literal may be treated as plain JavaScript rather than literal content, potentially bypassing the package’s context-aware escaping and enabling cross-site scripting in applications that render HTML.

Stay up to date with KrakenD releases and important updates