News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-39827 Medium False Positive

ssh: Memory Leak via Repeatedly Rejected Channels Enables Server DoS

This CVE does not affect KrakenD

KrakenD does not implement or expose SSH functionality. The golang.org/x/crypto/ssh package is a transitive dependency but its SSH server code paths are never invoked during KrakenD operation. The dependency was upgraded as a precaution.

Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.

Component

golang.org/x/crypto (SSH)

Disclosed

May 26, 2026

Description

Go’s golang.org/x/crypto/ssh server leaks memory when an authenticated client repeatedly opens and has channels rejected. Over time, this accumulated memory leak can exhaust server resources, leading to denial of service.

Stay up to date with KrakenD releases and important updates