News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-40179
CVE
Medium
· CVSS 6.1
False Positiveprometheus/client_golang) to expose
a /metrics scrape endpoint and does not embed or serve the Prometheus web UI.
The vulnerable JavaScript rendering components are part of the Prometheus server
application, which KrakenD does not include. The dependency was upgraded as a
precaution.Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.
Component
Prometheus client library
Disclosed
May 11, 2026
CVSS Score
6.1
innerHTML without HTML escaping. An attacker with the ability to write
metrics — via remote write, OTLP, or compromised scrape targets — can inject
arbitrary JavaScript that executes in users’ browsers when they view the Prometheus
web UI.Stay up to date with KrakenD releases and important updates