CVE-2026-39832
Medium
False Positivegolang.org/x/crypto/ssh/agent package is a transitive dependency but its
code paths are never invoked during KrakenD operation. The dependency was
upgraded as a precaution.Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.
Component
golang.org/x/crypto (SSH)
Disclosed
May 26, 2026
golang.org/x/crypto/ssh/agent silently drops destination constraints
when forwarding keys to a remote agent. Keys with destination restrictions can
be used at unintended destinations, bypassing the intended forwarding controls.Stay up to date with KrakenD releases and important updates