CVE-2026-42506
Medium
False Positivegolang.org/x/net/html to parse or
render HTML content from user requests. The vulnerable HTML parsing code path is
never invoked during KrakenD operation.Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.
Component
golang.org/x/net (html)
Disclosed
May 26, 2026
golang.org/x/net/html package incorrectly handles namespaced elements inside
foreign content (MathML and SVG contexts), potentially allowing cross-site scripting
when parsed HTML is re-serialized without proper handling of namespace boundaries.Stay up to date with KrakenD releases and important updates