News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-39830 Medium False Positive

ssh: Server Deadlock via Unsolicited Global Request Responses

This CVE does not affect KrakenD

KrakenD does not implement or expose SSH functionality. The golang.org/x/crypto/ssh package is a transitive dependency but its SSH server code paths are never invoked during KrakenD operation. The dependency was upgraded as a precaution.

Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.

Component

golang.org/x/crypto (SSH)

Disclosed

May 26, 2026

Description

Go’s golang.org/x/crypto/ssh server can enter a deadlock when a client fills the internal buffer with unsolicited global request responses. This causes the server goroutine to stall indefinitely, denying service to affected connections.

Stay up to date with KrakenD releases and important updates