CVE-2026-39830
Medium
False Positivegolang.org/x/crypto/ssh package is a transitive dependency but its SSH server
code paths are never invoked during KrakenD operation. The dependency was upgraded
as a precaution.Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.
Component
golang.org/x/crypto (SSH)
Disclosed
May 26, 2026
golang.org/x/crypto/ssh server can enter a deadlock when a client fills
the internal buffer with unsolicited global request responses. This causes the
server goroutine to stall indefinitely, denying service to affected connections.Stay up to date with KrakenD releases and important updates