CVE-2026-6993Medium· 5.3▾ SunlitA flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended inter…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
Last analysed / modified upstream
A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's NewServer function, specifically within the http.DefaultServeMux Fallback Handler. This manipulation creates an unintended intermediary, which can lead to the disclosure of sensitive information.
go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary — rated Moderate by Red Hat. Released 2026-04-25, updated 2026-09-18.
Affected:
No fix planned:
Out of support scope
Workarounds / mitigations:
go-kratos HTTP server to only trusted clients or internal networks by configuring appropriate firewall rules. If the go-kratos service is not required, consider disabling it. Any changes to network configurations or service states may require a service reload or restart to take effect, which could impact ongoing operations.Affected packages:
github.com/go-kratos/kratos/v2 <= 2.9.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-33194High· 7.5golang: x/net/html: infinite loop in ParseFragment (CVE-2021-33194)
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)
CVE-2026-37236Critical· 9.8grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control
CVE-2026-56855Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted messages (CVE-2026-56855)
CVE-2026-78662Medium· 5.3golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via channel request flooding (CVE-2026-78662)