← العودة للجدول
CVE-2026-34612
CVE-2026-34612 — VulnCheck: Kestra is an open-source, event-driven orchestration platform. Prior t
📅 2026-04-03
🔴 Critical 🔥 No VulnCheck Exploit Containers CVSS 9.9

📋 الوصف الكامل

Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authenticated, simply visiting a crafted link is enough to trigger the vulnerability. The injected payloa

💻 الأنظمة المتأثرة

Docker | PostgreSQL

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-34612

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v1.3.7

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←