CRITICAL
Kestra
CVE published 2026-05-05
CVE-2026-38428
CVE-2026-38428 is a SQL injection vulnerability in Kestra versions 1.3.3 and before. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9. [truncated]