CVE-2026-42507
Medium
Medium ImpactThis CVE can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.
Component
Go standard library (net/textproto)
Disclosed
Jun 3, 2026
net/textproto package included raw user-controlled input in error messages without
any escaping. The net/http client uses ReadMIMEHeader to parse response headers from
servers, so a malicious backend server can inject arbitrary content — including terminal
control bytes — into KrakenD’s error output or logs.
This can lead to log injection, log spoofing, or manipulation of log-based monitoring systems.Community Edition
2.13.7
addresses this CVE
Affected CE versions
>= 2.0, < 2.13.7
Enterprise Edition
2.13.5
addresses this CVE
Affected EE versions
>= 2.0, < 2.13.5
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates