PatchSiren

Kestra CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Kestra CVE published 2026-05-05

CVE-2026-38428

CVE-2026-38428 is a SQL injection vulnerability in Kestra versions 1.3.3 and before. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. This allows attackers to inject arbitrary SQL expressions into the database query. The affected versions are Kestra v1.3.3 and before. The CVSS score is 9. [truncated]