Technology · Kestra
Kestra vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 12 vulnerabilities in Kestra: 0 in the last 7 days and 4 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55839, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 3
- Exploited in the wild
- 0
About Kestra
Open-source workflow orchestration and scheduling platform for building and managing data pipelines.
Latest Kestra vulnerabilities
- CVE-2026-55839: Kestra stored XSS via custom Markdown link attribute injectionhighCVSS 8.7EPSS 0.4%
- CVE-2026-73247: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's…highCVSS 8.6EPSS 0.4%
- CVE-2026-73246: Kestra unauthenticated worker endpoint exposes task credentialshighCVSS 7.5EPSS 0.6%
- CVE-2026-73245: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's…mediumCVSS 6.5EPSS 0.3%
- CVE-2026-55069: Kestra OSS weak password hashing in BasicAuth componenthighCVSS 8.7
- CVE-2026-53577: Kestra access control bypass in previewFileFromExecution endpointmediumCVSS 6.5
- CVE-2026-53576: Kestra authentication bypass and RCE via path-suffix manipulationcriticalCVSS 10
- CVE-2026-49984: Kestra path traversal in LocalStorage via backslash smugglinghighCVSS 7.7
- CVE-2026-45807: Kestra path traversal via URL-encoded characters in API endpointshighCVSS 7.7
- CVE-2026-48129: Kestra path traversal in inputFiles task propertymediumCVSS 6.5
- CVE-2026-38428: Kestra SQL injection in flow search API leading to RCEcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-34612: Kestra SQL injection in flow search leads to RCEcriticalCVSS 9.9EPSS 0.7%
Most severe Kestra vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-53576: Kestra authentication bypass and RCE via path-suffix manipulationcriticalCVSS 10
- CVE-2026-34612: Kestra SQL injection in flow search leads to RCEcriticalCVSS 9.9EPSS 0.7%
- CVE-2026-38428: Kestra SQL injection in flow search API leading to RCEcriticalCVSS 9.8EPSS 0.4%
- CVE-2026-55839: Kestra stored XSS via custom Markdown link attribute injectionhighCVSS 8.7EPSS 0.4%
- CVE-2026-55069: Kestra OSS weak password hashing in BasicAuth componenthighCVSS 8.7
- CVE-2026-73247: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's…highCVSS 8.6EPSS 0.4%
- CVE-2026-49984: Kestra path traversal in LocalStorage via backslash smugglinghighCVSS 7.7
- CVE-2026-45807: Kestra path traversal via URL-encoded characters in API endpointshighCVSS 7.7
- CVE-2026-73246: Kestra unauthenticated worker endpoint exposes task credentialshighCVSS 7.5EPSS 0.6%
- CVE-2026-73245: Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's…mediumCVSS 6.5EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 3 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/kestra.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Kestra vulnerabilities", https://junglewise.ai/threats/technologies/kestra, 26 September 2026.