CVE-2026-6993

Source
https://cve.org/CVERecord?id=CVE-2026-6993
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6993.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6993
Aliases
Published
2026-04-25T18:30:16.160Z
Modified
2026-07-24T19:11:20.157371545Z
Severity
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
go-kratos http.DefaultServeMux Fallback server.go NewServer confused deputy
Details

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended intermediary. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The patch is identified as 0284a5bcf92b5a7ee015300ce3051baf7ae4718d. Applying a patch is advised to resolve this issue.

Database specific
{
    "cwe_ids": [
        "CWE-441"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6993.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/yanhu007/kratos

Affected ranges

Type
GIT
Repo
https://github.com/yanhu007/kratos
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.9.0"
        },
        {
            "last_affected": "2.9.0"
        },
        {
            "introduced": "2.9.1"
        },
        {
            "last_affected": "2.9.1"
        },
        {
            "introduced": "2.9.2"
        },
        {
            "last_affected": "2.9.2"
        }
    ]
}

Affected versions

2.*
2.9.0
2.9.1
2.9.2
v2.*
v2.9.0
v2.9.1
v2.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6993.json"