News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-42506 Medium False Positive

html: XSS via Namespaced Elements in Foreign Content

This CVE does not affect KrakenD

KrakenD is an API gateway and does not use golang.org/x/net/html to parse or render HTML content from user requests. The vulnerable HTML parsing code path is never invoked during KrakenD operation.

Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.

Component

golang.org/x/net (html)

Disclosed

May 26, 2026

Description

Go’s golang.org/x/net/html package incorrectly handles namespaced elements inside foreign content (MathML and SVG contexts), potentially allowing cross-site scripting when parsed HTML is re-serialized without proper handling of namespace boundaries.

Stay up to date with KrakenD releases and important updates