News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-42501 Medium False Positive

cmd/go: Malicious Module Proxy Can Bypass Checksum Database

This CVE does not affect KrakenD

This is a build-time vulnerability in the Go build tool (cmd/go). KrakenD distributes pre-compiled binaries and does not invoke go build or go get at runtime. End users running KrakenD as a gateway are not affected.

Addressed through routine dependency maintenance in CE 2.13.5 and EE 2.13.3.

Component

Go standard library (cmd/go)

Disclosed

May 11, 2026

Description

Go’s cmd/go build tool can be made to bypass the checksum database when a malicious module proxy manipulates the module download flow. This could allow a compromised proxy to serve unverified module content during a go get or build operation.

Stay up to date with KrakenD releases and important updates