CVE-2026-42501
Medium
False Positivecmd/go). KrakenD
distributes pre-compiled binaries and does not invoke go build or go get
at runtime. End users running KrakenD as a gateway are not affected.Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.
Component
Go standard library (cmd/go)
Disclosed
May 11, 2026
cmd/go build tool can be made to bypass the checksum database when a
malicious module proxy manipulates the module download flow. This could allow a
compromised proxy to serve unverified module content during a go get or build
operation.Stay up to date with KrakenD releases and important updates