News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released

CVE-2026-42154 CVE High · CVSS 7.5 False Positive

Prometheus: Memory Exhaustion via Crafted Remote Read Request

This advisory does not affect KrakenD

KrakenD uses the Prometheus client library (prometheus/client_golang) for exposing metrics at a /metrics endpoint. The vulnerable remote read API (/api/v1/read) is a feature of the Prometheus server binary and is not implemented or exposed by KrakenD. The dependency was upgraded as a precaution.

Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.

Component

Prometheus client library

Disclosed

May 11, 2026

CVSS Score

7.5

Description

The Prometheus remote read endpoint (/api/v1/read) fails to validate the declared decoded length of snappy-compressed request bodies before allocating memory. An unauthenticated attacker can send a small payload that triggers excessive heap allocation per request, potentially exhausting memory and crashing the process under concurrent load.

Stay up to date with KrakenD releases and important updates