CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*

History

08 May 2026, 19:24

Type Values Removed Values Added
CPE cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
First Time Kestra
Kestra kestra
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x - () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x - Exploit, Mitigation, Vendor Advisory
References () https://www.link.com - () https://www.link.com - Not Applicable

06 May 2026, 16:16

Type Values Removed Values Added
References () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x - () https://github.com/kestra-io/kestra/security/advisories/GHSA-365w-2m69-mp9x -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

05 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 19:16

Updated : 2026-05-08 19:24


NVD link : CVE-2026-38428

Mitre link : CVE-2026-38428

CVE.ORG link : CVE-2026-38428


JSON object : View

Products Affected

kestra

  • kestra
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')