Where
-Infinity
0

Kestra KestraKestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

Risk 49
Severity
8.6
First published (updated )

Kestra KestraKestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth

Risk 40
Severity
6.5
First published (updated )

Kestra Kestra OSSKestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`

Risk 87
Severity
10
First published (updated )

Kestra KestraKestra: Path traversal via URL-encoded "%2E%2E" in execution and namespace file endpoints allows arbitrary file read

Risk 44
Severity
7.7
First published (updated )

Kestra KestraKestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)

Risk 44
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Kestra KestraKestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass

Risk 87
Severity
10
First published (updated )

Kestra KestraKestra: Cross-Execution File Read via Preview Endpoint (IDOR)

Risk 38
Severity
6.5
First published (updated )

Kestra Kestra OSS workflow orchestration platformKestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack

Risk 64
Severity
8.7
First published (updated )

Kestra KestraKestra task inputFiles accepts traversal filenames for worker file writes

Risk 45
Severity
6.5
First published (updated )

Kestra KestraSQL Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Kestra KestraKestra: Remote Code Execution via SQL Injection

Risk 83
Severity
10
First published (updated )

Kestra KestraKestra Vulnerable to Stored Cross-Site Scripting via Flow YAML Fields

Risk 39
Severity
7.3
EPSS
0.04%
First published (updated )

npm/kestraKestra: Stored Cross-Site Scripting in Markdown File Preview

Risk 39
Severity
7.3
EPSS
0.04%
First published (updated )

Kestra KestraKestra allows Stored XSS before 0.22

Risk 24
Severity
4.2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203