News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-34986
CVE
High
· CVSS 7.5
False Positiveauth/validator component does not implement JWE (JSON Web Encryption)
support. The vulnerability exists in the JWE processing path of the underlying library,
which KrakenD never invokes. The library was upgraded as a precaution.Addressed through routine dependency maintenance in CE 2.13.4 and EE 2.13.2.
Component
auth/validator
Disclosed
Apr 8, 2026
CVSS Score
7.5
encrypted_key field. The cipher.KeyUnwrap() call attempts to
allocate a slice with invalid length parameters, causing an unhandled exception and
crashing the process. Affects go-jose v3.0.0–3.0.4 and v4.0.0–4.1.3.Stay up to date with KrakenD releases and important updates