CVE-2026-39819
Medium
False Positivecmd/go). KrakenD
distributes pre-compiled binaries and does not invoke the Go toolchain at runtime.
End users running KrakenD as a gateway are not affected.Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.
Component
Go standard library (cmd/go)
Disclosed
May 11, 2026
cmd/go go bug subcommand creates temporary files with predictable names
and follows symbolic links, allowing a local attacker to redirect file operations
to arbitrary locations on the filesystem via a symlink attack.Stay up to date with KrakenD releases and important updates