Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6993

Опубликовано: 25 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue.

A flaw was found in go-kratos kratos. A remote attacker could exploit a vulnerability in the HTTP server's NewServer function, specifically within the http.DefaultServeMux Fallback Handler. This manipulation creates an unintended intermediary, which can lead to the disclosure of sensitive information.

Меры по смягчению последствий

To reduce exposure, restrict network access to the go-kratos HTTP server to only trusted clients or internal networks by configuring appropriate firewall rules. If the go-kratos service is not required, consider disabling it. Any changes to network configurations or service states may require a service reload or restart to take effect, which could impact ongoing operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Builds for Red Hat OpenShiftopenshift-builds/openshift-builds-waiters-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Compliance Operatorcompliance/openshift-compliance-operator-bundleFix deferred
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9-operatorFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Deployment Validation Operatordvo/deployment-validation-rhel8-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2461841net/http: golang: github.com/go-kratos/kratos: go-kratos kratos: Information disclosure via unintended HTTP server intermediary

EPSS

Процентиль: 24%
0.00315
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue.

CVSS3: 5.3
github
3 месяца назад

Kratos has a Confused Deputy issue

EPSS

Процентиль: 24%
0.00315
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-6993