io.kestra:kestra
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.kestra:kestrapage 1 of 1
- CVE-2026-55839HIGHCVSS 8.7EG 8.7fixed in 1.3.242026-08-18
vulnerable: 0.10.0 ... 1.3.9 (486 versions)
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update a Flow description to inject JavaScr…
- CVE-2026-73245MEDIUMCVSS 6.5EG 6.5fixed in 2.0.02026-08-11
vulnerable: 0.10.0 ... 2.0.0-rc9 (509 versions)
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /api…
Check whether io.kestra:kestra is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.kestra:kestra CVEs against the assets you own.
Book a Demo →