Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kestra HIGH 8.7
CVE-2026-55069

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component o…

Fix: 1.3.24+
Fix from $1,950 2026-06-26
Kestra CRITICAL 10.0
CVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Kestra CRITICAL 10.0
CVE-2026-53576

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Kestra HIGH 7.7
CVE-2026-49984

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied…

Fix: 1.0.45 / 1.3.23+
Fix from $1,950 2026-06-26
Kestra MEDIUM 6.5
CVE-2026-53577

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant…

Fix: 1.0.45 / 1.3.21+
Fix from $1,600 2026-06-26
Kestra HIGH 7.7
CVE-2026-45807

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from t…

Fix: 1.0.43 / 1.3.19+
Fix from $1,950 2026-06-26
Kestra CRITICAL 9.8
CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly conc…

Fix: 1.0.35 / 1.3.7+
Fix from $2,300 2026-05-05
Kestra CRITICAL 9.0
CVE-2026-34612

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje…

Fix: 1.3.7+
Fix from $2,300 2026-04-03
Kestra MEDIUM 5.4
CVE-2026-33664

Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — des…

Fix: after 1.3.3
Fix from $1,600 2026-03-26
Kestra MEDIUM 5.4
CVE-2026-29082

Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (…

Fix: after 1.1.10
Fix from $1,600 2026-03-06