News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-39826
CVE
Medium
False Positivehtml/template package to
generate HTML responses. The vulnerable code path in html/template is never
invoked during normal KrakenD operation.Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.
Component
Go standard library (html/template)
Disclosed
May 11, 2026
html/template package contains an escaper bypass where certain template
patterns allow injecting unescaped content into HTML output. Applications using
these specific template constructs to render user-controlled data are vulnerable
to cross-site scripting attacks.Stay up to date with KrakenD releases and important updates