VulnSea

kestra has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 8.6 (high), with 1 rated critical. Most affected products: io.kestra:kestra (2), io.kestra:core (1), kestra (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
25% vs 1% corpus
Median CVSS
8.6
Publish → KEV
(1)
Last 90 days
4 prev 0

Products

  • io.kestra:kestra 2
  • io.kestra:core 1
  • kestra 1
4
Total CVEs
1
Critical
1
CISA KEV
1
Exploited

kestra vulnerabilities

CVEs affecting kestra, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-55839High· 8.7
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaS…

Twilightkestra · io.kestra:kestraEPSS 0.30%via NVD
CVE-2026-73247High· 8.6
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the s…

Twilightkestra · io.kestra:coreEPSS 0.37%via NVD
CVE-2026-73245Medium· 6.5
1mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /a…

Sunlitkestra · io.kestra:kestraEPSS 0.23%via NVD
CVE-2026-49869Critical· 10.0CISA KEVPoC
2mo ago

Kestra is an open-source, event-driven orchestration platform

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Bec…

Hadalkestra · kestraEPSS 1.9%via NVD
kestra vulnerabilities (CVEs) · VulnSea