Kestra is an open-source workflow orchestration and automation platform whose vulnerability surface is limited to the core product and centers on application-layer input-handling issues such as cross-site scripting and SQL injection. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kestra over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49869CRITICAL Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whiteli | Jun 26, 2026 | 10.0 | 45 | NO | NO |
CVE-2026-53576CRITICAL Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request who | Jun 26, 2026 | 10.0 | 44 | NO | NO |
CVE-2026-55069HIGH Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orche | Jun 26, 2026 | 8.7 | 39 | NO | NO |
CVE-2026-38428CRITICAL Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query with | May 5, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-45807HIGH Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints accept a kestra:// URI from the client and pass it through S | Jun 26, 2026 | 7.7 | 36 | NO | NO |
CVE-2026-49984HIGH Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before | Jun 26, 2026 | 7.7 | 36 | NO | NO |
CVE-2026-53577MEDIUM Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file | Jun 26, 2026 | 6.5 | 32 | NO | NO |
CVE-2026-34612CRITICAL Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads | Apr 3, 2026 | 9.0 | 32 | NO | NO |
CVE-2026-33664MEDIUM Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied flow YAML metadata fields — description, inputs[].displayName, | Mar 26, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-29082MEDIUM Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview renders user-supplied Markdown (.md) with markdown-it instantia | Mar 6, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kestra.
Media articles that mention a CVE ID that affects a product developed by Kestra — matched by CVE ID, not by vendor name.