News KrakenD Partners with Digital Platform Solutions to Expand Reach in Pakistan

CVE-2026-46597 Medium False Positive

ssh: Byte Arithmetic Underflow in AES-GCM Packet Decoder

This CVE does not affect KrakenD

KrakenD does not implement or expose SSH functionality. The golang.org/x/crypto/ssh package is a transitive dependency but its SSH server code paths are never invoked during KrakenD operation. The dependency was upgraded as a precaution.

Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.

Component

golang.org/x/crypto (SSH)

Disclosed

May 26, 2026

Description

A byte arithmetic underflow in Go’s golang.org/x/crypto/ssh AES-GCM packet decoder can cause a server-side panic when a client sends a specially crafted AES-GCM-encrypted SSH packet. This can be triggered pre-authentication, enabling an unauthenticated attacker to crash an SSH server.

Stay up to date with KrakenD releases and important updates