News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation News KrakenD Partners with CGK Solutions to Secure API Integration in Italy Case Study Every Change Reviewed, Every Peak Absorbed: Paribu's API Gateway News KrakenD CE v3.0 Released
CVE-2026-42154
CVE
High
· CVSS 7.5
False Positiveprometheus/client_golang) for
exposing metrics at a /metrics endpoint. The vulnerable remote read API
(/api/v1/read) is a feature of the Prometheus server binary and is not
implemented or exposed by KrakenD. The dependency was upgraded as a precaution.Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.
Component
Prometheus client library
Disclosed
May 11, 2026
CVSS Score
7.5
/api/v1/read) fails to validate the declared
decoded length of snappy-compressed request bodies before allocating memory. An
unauthenticated attacker can send a small payload that triggers excessive heap
allocation per request, potentially exhausting memory and crashing the process
under concurrent load.Stay up to date with KrakenD releases and important updates