CVE-2026-46597
Medium
False Positivegolang.org/x/crypto/ssh package is a transitive dependency but its SSH server
code paths are never invoked during KrakenD operation. The dependency was upgraded
as a precaution.Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.
Component
golang.org/x/crypto (SSH)
Disclosed
May 26, 2026
golang.org/x/crypto/ssh AES-GCM packet
decoder can cause a server-side panic when a client sends a specially crafted
AES-GCM-encrypted SSH packet. This can be triggered pre-authentication, enabling
an unauthenticated attacker to crash an SSH server.Stay up to date with KrakenD releases and important updates