io.kestra:kestra vulnerabilities
CVEs whose affected-version data names the io.kestra:kestra package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55839High· 8.7Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…
▾ Twilightkestra · io.kestra:kestraEPSS 0.43%via NVD
CVE-2026-73245Medium· 6.5Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…
▾ Sunlitkestra · io.kestra:kestraEPSS 0.33%via NVD