{"id":"CVE-2026-6993","title":"go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary (CVE-2026-6993)","summary":"A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cvssSource":"vendor","cwe":"CWE-444","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","builds_for_red_hat_openshift","cert_manager_operator_for_red_hat_openshift","compliance_operator","confidential_compute_attestation","cryostat 4","custom_metric_autoscaler_operator_for_red_hat_openshift","deployment_validation_operator","external_secrets_operator_for_red_hat_openshift","externaldns_operator","fence_agents_remediation_operator","file_integrity_operator","gatekeeper 3","logging_subsystem_for_red_hat_openshift","logical_volume_manager_storage","machine_deletion_remediation_operator","migration_toolkit_for_applications 8","migration_toolkit_for_containers","multiarch_tuning_operator","multicluster_engine_for_kubernetes","multicluster_global_hub","network_observability_operator","node_healthcheck_operator","openshift_api_for_data_protection","openshift_developer_tools_and_services","openshift_lightspeed","openshift_pipelines","openshift_serverless","openshift_service_mesh 2","openshift_service_mesh 3","openshift_source_to_image_s2i","power_monitoring_for_red_hat_openshift","3scale_api_management_platform 2","advanced_cluster_management_for_kubernetes 2","advanced_cluster_security 4","amq_broker 7","ansible_automation_platform 2","build_of_apache_camel_hawtio 4","build_of_apicurio_registry 2","ceph_storage 5"],"published":"2026-04-25","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:36:38+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-6993"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461841"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-6993"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6993"},{"url":"https://github.com/Yanhu007/kratos/commit/0284a5bcf92b5a7ee015300ce3051baf7ae4718d"},{"url":"https://github.com/go-kratos/kratos/"},{"url":"https://github.com/go-kratos/kratos/issues/3810"},{"url":"https://github.com/go-kratos/kratos/pull/3814"},{"url":"https://vuldb.com/submit/797099"},{"url":"https://vuldb.com/vuln/359545"},{"url":"https://vuldb.com/vuln/359545/cti"},{"url":"https://github.com/go-kratos/kratos"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00315,"epssPercentile":0.24614,"aliases":["GHSA-jj45-xvq5-rhh9","GO-2026-5471"],"ecosystem":"go","ingestedAt":"2026-07-25T19:08:11.623Z","slug":"CVE-2026-6993","body":"## Overview\n\nA flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended intermediary, which can lead to the disclosure of sensitive information.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, Cryostat 4, … · no fix planned: Red Hat Enterprise Linux 9, Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json)\n\n**go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary** — rated Moderate by Red Hat. Released 2026-04-25, updated 2026-09-18.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n- Compliance Operator\n- Confidential Compute Attestation\n- Cryostat 4\n- Custom Metric Autoscaler operator for Red Hat Openshift\n- Deployment Validation Operator\n- External Secrets Operator for Red Hat OpenShift\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- File Integrity Operator\n- Gatekeeper 3\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- OpenShift Source-to-Image (S2I)\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 2\n- Red Hat Ceph Storage 5\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 9\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Builds for Red Hat OpenShift\n- cert-manager Operator for Red Hat OpenShift\n- Compliance Operator\n- Confidential Compute Attestation\n- Cryostat 4\n- Custom Metric Autoscaler operator for Red Hat Openshift\n- Deployment Validation Operator\n- External Secrets Operator for Red Hat OpenShift\n- ExternalDNS Operator\n- Fence Agents Remediation Operator\n- File Integrity Operator\n- Gatekeeper 3\n- Logging Subsystem for Red Hat OpenShift\n- Logical Volume Manager Storage\n- Machine Deletion Remediation Operator\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Multiarch Tuning Operator\n- Multicluster Engine for Kubernetes\n- Multicluster Global Hub\n- Network Observability Operator\n- Node HealthCheck Operator\n- OpenShift API for Data Protection\n- OpenShift Developer Tools and Services\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- OpenShift Serverless\n- OpenShift Service Mesh 2\n- OpenShift Service Mesh 3\n- OpenShift Source-to-Image (S2I)\n- Power monitoring for Red Hat OpenShift\n- Red Hat 3scale API Management Platform 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 4\n- Red Hat AMQ Broker 7\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apache Camel - HawtIO 4\n- Red Hat build of Apicurio Registry 2\n\n## Remediation\n\nOut of support scope\n\nWorkarounds / mitigations:\n\n- To reduce exposure, restrict network access to the `go-kratos` HTTP server to only trusted clients or internal networks by configuring appropriate firewall rules. If the `go-kratos` service is not required, consider disabling it. Any changes to network configurations or service states may require a service reload or restart to take effect, which could impact ongoing operations.\n\n## Package advisory (CVE-2026-6993)\n\nAffected packages:\n\n- `github.com/go-kratos/kratos/v2 <= 2.9.2`\n\nSource: https://osv.dev/vulnerability/GHSA-jj45-xvq5-rhh9","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}