Known Vulnerabilities for Kestra by Kestra-io
Listed below are 9 of the newest known vulnerabilities associated with "Kestra" by "Kestra-io".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55069 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth au... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-53577 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpo... | Not Provided | 2026-06-26 | 2026-06-27 |
| CVE-2026-53576 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the ... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-49984 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-49869 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-48129 json | Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra t... | Not Provided | 2026-06-19 | 2026-06-23 |
| CVE-2026-45807 json | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accep... | Not Provided | 2026-06-26 | 2026-06-26 |
| CVE-2026-38428 json | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET pa... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-34612 json | Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deploym... | Not Provided | 2026-04-03 | 2026-04-06 |