CVE-2026-84304
CVE
High
· CVSS 7.5
Medium ImpactThis vulnerability can affect KrakenD under specific conditions. Review the affected versions below and upgrade if your deployment is exposed.
grpc server exposes gRPC methods to external clients, which lets an unauthenticated
caller reach the vulnerable transport directly. The backend/grpc client and the
OTLP/gRPC exporter of telemetry/opentelemetry reach the same receive path from a
malicious or compromised upstream or collector. Deployments that expose no gRPC
server and use no gRPC backend or OTLP/gRPC exporter are not exposed.Component
gRPC for Go (grpc-go)
Disclosed
Sep 7, 2026
CVSS Score
7.5
grpc-go 1.83.1.Community Edition
2.13.11
addresses this advisory
Affected CE versions
>= 2.0, < 2.13.11
Enterprise Edition
2.13.9
addresses this advisory
Affected EE versions
>= 2.0, < 2.13.9
Upgrade to the addressed version or later to remediate this vulnerability.
Stay up to date with KrakenD releases and important updates