News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-32952 High · CVSS 7.5 High Impact

auth/ntlm: Process Crash via Malicious NTLM Challenge Message

Exploitable

This CVE is exploitable in typical deployments. Upgrade to the fixed version as soon as possible.

Component

auth/ntlm (go-ntlmssp)

Disclosed

May 11, 2026

CVSS Score

7.5

Description

The go-ntlmssp library used by KrakenD’s auth/ntlm component contains an integer overflow that causes a slice out-of-bounds panic when a malicious NTLM challenge message is received. Any Go process using ntlmssp.Negotiator as an HTTP transport can be crashed by a malicious server sending a crafted NTLM challenge, enabling unauthenticated denial of service against the KrakenD process.

Version summary

Community Edition

Not affected

Enterprise Edition

2.13.3

addresses this CVE

Affected EE versions

>= 2.0, < 2.13.3

Upgrade to the addressed version or later to remediate this vulnerability.

Stay up to date with KrakenD releases and important updates