---
id: CVE-2026-6993
title: >-
  go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server
  intermediary (CVE-2026-6993)
summary: >-
  A flaw was found in go-kratos kratos. A remote attacker could exploit a
  vulnerability in the HTTP server's `NewServer` function, specifically within
  the `http.DefaultServeMux Fallback Handler`. This manipulation creates an
  unintended inter…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cvssSource: vendor
cwe: CWE-444
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - assisted_installer_for_red_hat_openshift_container_platform 2
  - builds_for_red_hat_openshift
  - cert_manager_operator_for_red_hat_openshift
  - compliance_operator
  - confidential_compute_attestation
  - cryostat 4
  - custom_metric_autoscaler_operator_for_red_hat_openshift
  - deployment_validation_operator
  - external_secrets_operator_for_red_hat_openshift
  - externaldns_operator
  - fence_agents_remediation_operator
  - file_integrity_operator
  - gatekeeper 3
  - logging_subsystem_for_red_hat_openshift
  - logical_volume_manager_storage
  - machine_deletion_remediation_operator
  - migration_toolkit_for_applications 8
  - migration_toolkit_for_containers
  - multiarch_tuning_operator
  - multicluster_engine_for_kubernetes
  - multicluster_global_hub
  - network_observability_operator
  - node_healthcheck_operator
  - openshift_api_for_data_protection
  - openshift_developer_tools_and_services
  - openshift_lightspeed
  - openshift_pipelines
  - openshift_serverless
  - openshift_service_mesh 2
  - openshift_service_mesh 3
  - openshift_source_to_image_s2i
  - power_monitoring_for_red_hat_openshift
  - 3scale_api_management_platform 2
  - advanced_cluster_management_for_kubernetes 2
  - advanced_cluster_security 4
  - amq_broker 7
  - ansible_automation_platform 2
  - build_of_apache_camel_hawtio 4
  - build_of_apicurio_registry 2
  - ceph_storage 5
published: '2026-04-25'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:36:38+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-6993'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2461841'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-6993'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6993'
  - url: >-
      https://github.com/Yanhu007/kratos/commit/0284a5bcf92b5a7ee015300ce3051baf7ae4718d
  - url: 'https://github.com/go-kratos/kratos/'
  - url: 'https://github.com/go-kratos/kratos/issues/3810'
  - url: 'https://github.com/go-kratos/kratos/pull/3814'
  - url: 'https://vuldb.com/submit/797099'
  - url: 'https://vuldb.com/vuln/359545'
  - url: 'https://vuldb.com/vuln/359545/cti'
  - url: 'https://github.com/go-kratos/kratos'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.00537
epssPercentile: 0.42762
aliases:
  - GHSA-jj45-xvq5-rhh9
  - GO-2026-5471
ecosystem: go
ingestedAt: '2026-07-25T19:08:11.623Z'
---

## Overview

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's `NewServer` function, specifically within the `http.DefaultServeMux Fallback Handler`. This manipulation creates an unintended intermediary, which can lead to the disclosure of sensitive information.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, Compliance Operator, Confidential Compute Attestation, Cryostat 4, … · no fix planned: Red Hat Enterprise Linux 9, Assisted Installer for Red Hat OpenShift Container Platform 2, Builds for Red Hat OpenShift, cert-manager Operator for Red Hat OpenShift, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6993.json)

**go-kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary** — rated Moderate by Red Hat. Released 2026-04-25, updated 2026-09-18.

Affected:

- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Custom Metric Autoscaler operator for Red Hat Openshift
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- ExternalDNS Operator
- Fence Agents Remediation Operator
- File Integrity Operator
- Gatekeeper 3
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- OpenShift Source-to-Image (S2I)
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 2
- Red Hat Ceph Storage 5

No fix planned:

- Red Hat Enterprise Linux 9
- Assisted Installer for Red Hat OpenShift Container Platform 2
- Builds for Red Hat OpenShift
- cert-manager Operator for Red Hat OpenShift
- Compliance Operator
- Confidential Compute Attestation
- Cryostat 4
- Custom Metric Autoscaler operator for Red Hat Openshift
- Deployment Validation Operator
- External Secrets Operator for Red Hat OpenShift
- ExternalDNS Operator
- Fence Agents Remediation Operator
- File Integrity Operator
- Gatekeeper 3
- Logging Subsystem for Red Hat OpenShift
- Logical Volume Manager Storage
- Machine Deletion Remediation Operator
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Multiarch Tuning Operator
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- Network Observability Operator
- Node HealthCheck Operator
- OpenShift API for Data Protection
- OpenShift Developer Tools and Services
- OpenShift Lightspeed
- OpenShift Pipelines
- OpenShift Serverless
- OpenShift Service Mesh 2
- OpenShift Service Mesh 3
- OpenShift Source-to-Image (S2I)
- Power monitoring for Red Hat OpenShift
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 4
- Red Hat AMQ Broker 7
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apache Camel - HawtIO 4
- Red Hat build of Apicurio Registry 2

## Remediation

Out of support scope

Workarounds / mitigations:

- To reduce exposure, restrict network access to the `go-kratos` HTTP server to only trusted clients or internal networks by configuring appropriate firewall rules. If the `go-kratos` service is not required, consider disabling it. Any changes to network configurations or service states may require a service reload or restart to take effect, which could impact ongoing operations.

## Package advisory (CVE-2026-6993)

Affected packages:

- `github.com/go-kratos/kratos/v2 <= 2.9.2`

Source: https://osv.dev/vulnerability/GHSA-jj45-xvq5-rhh9
