Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/go-kratos/kratos/v2
  4. ›
  5. CVE-2026-6993

CVE-2026-6993: Kratos has a Confused Deputy issue

April 25, 2026 (updated May 5, 2026)

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue.

References

  • github.com/Yanhu007/kratos/commit/0284a5bcf92b5a7ee015300ce3051baf7ae4718d
  • github.com/advisories/GHSA-jj45-xvq5-rhh9
  • github.com/go-kratos/kratos
  • github.com/go-kratos/kratos/issues/3810
  • github.com/go-kratos/kratos/pull/3814
  • nvd.nist.gov/vuln/detail/CVE-2026-6993
  • vuldb.com/submit/797099
  • vuldb.com/vuln/359545
  • vuldb.com/vuln/359545/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-6993 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.9.2

Solution

Unfortunately, there is no solution available yet.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

Source file

go/github.com/go-kratos/kratos/v2/CVE-2026-6993.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:18:28 +0000.