News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-39823 CVE Medium False Positive

html/template: Meta Content URL Escaping Bypass Causes XSS

This advisory does not affect KrakenD

KrakenD is an API gateway and does not use Go’s html/template package to generate HTML responses. The vulnerable code path in html/template is never invoked during normal KrakenD operation.

Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.

Component

Go standard library (html/template)

Disclosed

May 11, 2026

Description

Go’s html/template package fails to properly escape URLs in the content attribute of <meta> tags in certain template contexts, allowing an attacker controlling the template input to inject arbitrary URLs or JavaScript pseudo-protocol handlers into rendered HTML.

Stay up to date with KrakenD releases and important updates