News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-42151 CVE High · CVSS 7.5 False Positive

Prometheus: Azure AD OAuth Client Secret Exposed in Plaintext

This advisory does not affect KrakenD

KrakenD uses the Prometheus client library (prometheus/client_golang) for metrics exposition only. The Azure AD OAuth remote write configuration is a feature of the Prometheus server and is not part of KrakenD’s use of Prometheus. KrakenD does not expose the /-/config endpoint. The dependency was upgraded as a precaution.

Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.

Component

Prometheus client library

Disclosed

May 11, 2026

CVSS Score

7.5

Description

Prometheus stores the Azure AD OAuth client_secret as a plain string rather than a secured field, allowing any user or process with access to the /-/config HTTP API endpoint to read the credential in plaintext.

Stay up to date with KrakenD releases and important updates