CVE-2026-39882
Medium
· CVSS 5.3
Low ImpactExploiting this CVE requires an uncommon setup or configuration. Upgrading is still recommended when possible.
telemetry/opentelemetry in the KrakenD configuration
with an OTLP HTTP endpoint). Exploitation requires the ability to control or
intercept traffic to the configured OTLP collector endpoint.Component
telemetry/opentelemetry (OTLP HTTP exporters)
Disclosed
May 11, 2026
CVSS Score
5.3
Community Edition
2.13.5
addresses this CVE
Affected CE versions
>= 2.0, < 2.13.5
Enterprise Edition
2.13.3
addresses this CVE
Affected EE versions
>= 2.0, < 2.13.3
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates