Open-Source Event-Driven Orchestration Platform Vulnerability in Kestra
CVE-2026-73247
8.6HIGH
What is CVE-2026-73247?
Kestra, an open-source event-driven orchestration platform, is susceptible to a security flaw present in versions prior to 2.0.0. This vulnerability arises from the handling of user-controlled HTTP URIs that are passed to the URI.create() method and the server-side HTTP client without proper restriction on private, loopback, or link-local destinations. An unauthenticated attacker could exploit this vulnerability to import and execute a flow, gaining unauthorized access to internal services or cloud metadata, posing significant security risks for users.
Affected Version(s)
kestra < 2.0.0
