kestra has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.6 (high), with 1 rated critical. Most affected products: io.kestra:kestra (2), io.kestra:core (1), kestra (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 25% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —(1)
- Last 90 days
- 4 prev 0
Products
- io.kestra:kestra 2
- io.kestra:core 1
- kestra 1
Worst active — by depth score
CVE-2026-49869Critical· 10.0Kestra is an open-source, event-driven orchestration platform80CVE-2026-55839High· 8.7Kestra is an open-source, event-driven orchestration platform48CVE-2026-73247High· 8.6Kestra is an open-source, event-driven orchestration platform47CVE-2026-73245Medium· 6.5Kestra is an open-source, event-driven orchestration platform36
kestra vulnerabilities
CVEs affecting kestra, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-55839High· 8.7Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…
CVE-2026-73247High· 8.6Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the s…
CVE-2026-73245Medium· 6.5Kestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…
CVE-2026-49869Critical· 10.0CISA KEVPoCKestra is an open-source, event-driven orchestration platform
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…