CVE-2026-46598
Medium
False Positivegolang.org/x/crypto/ssh/agent package is a transitive dependency but its code
paths are never invoked during KrakenD operation. The dependency was upgraded as
a precaution.Addressed through routine dependency maintenance in CE 2.13.6 and EE 2.13.4.
Component
golang.org/x/crypto (SSH)
Disclosed
May 26, 2026
golang.org/x/crypto/ssh/agent client panics when processing pathological
inputs containing malformed ed25519 wire bytes, causing a crash of any application
using the SSH agent client.Stay up to date with KrakenD releases and important updates