News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-39817 CVE Medium False Positive

cmd/go: go tool pack Does Not Sanitize Output Paths

This advisory does not affect KrakenD

This is a build-time vulnerability in the Go build tool (cmd/go). KrakenD distributes pre-compiled binaries and does not invoke the Go toolchain at runtime. End users running KrakenD as a gateway are not affected.

Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.

Component

Go standard library (cmd/go)

Disclosed

May 11, 2026

Description

Go’s cmd/go go tool pack command does not sanitize output path names, allowing a maliciously crafted archive to write files to arbitrary locations outside the intended output directory via path traversal sequences in archive entry names.

Stay up to date with KrakenD releases and important updates