CVE-2026-56853
Medium
Medium ImpactThis CVE can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.
Component
Go standard library (net/http)
Disclosed
Aug 14, 2026
ReadHeaderTimeout, so a client that opens a connection and never sends data could
hold it open indefinitely. An attacker opening many such connections can exhaust
server resources, a slow-connection denial of service.Community Edition
2.13.9
addresses this CVE
Affected CE versions
>= 2.0, < 2.13.9
Enterprise Edition
2.13.7
addresses this CVE
Affected EE versions
>= 2.0, < 2.13.7
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates