Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-55069 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component o… Kestra 1.3.24+ Fix from $1,9502026-06-26 CRITICAL 10.0 CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 CRITICAL 10.0 CVE-2026-53576 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 HIGH 7.7 CVE-2026-49984 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied… Kestra 1.0.45 / 1.3.23+ Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-53577 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant… Kestra 1.0.45 / 1.3.21+ Fix from $1,6002026-06-26 HIGH 7.7 CVE-2026-45807 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from t… Kestra 1.0.43 / 1.3.19+ Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2026-38428 Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly conc… Kestra 1.0.35 / 1.3.7+ Fix from $2,3002026-05-05 CRITICAL 9.0 CVE-2026-34612 Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Inje… Kestra 1.3.7+ Fix from $2,3002026-04-03 MEDIUM 5.4 CVE-2026-33664 Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — des… Kestra after 1.3.3 Fix from $1,6002026-03-26 MEDIUM 5.4 CVE-2026-29082 Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (… Kestra after 1.1.10 Fix from $1,6002026-03-06