Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.
References
| Link | Resource |
|---|---|
| https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x | Exploit Mitigation Vendor Advisory |
| https://www.link.com | Not Applicable |
| https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x | Exploit Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 May 2026, 19:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:* | |
| First Time |
Kestra
Kestra kestra |
|
| References | () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x - Exploit, Mitigation, Vendor Advisory | |
| References | () https://www.link.com - Not Applicable |
06 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x - | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-89 |
05 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 19:16
Updated : 2026-05-08 19:24
NVD link : CVE-2026-38428
Mitre link : CVE-2026-38428
CVE.ORG link : CVE-2026-38428
JSON object : View
Products Affected
kestra
- kestra
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
