CVE-2026-38428

Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*
cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-05 19:16

Updated : 2026-07-24 21:10


NVD link : CVE-2026-38428

Mitre link : CVE-2026-38428

CVE.ORG link : CVE-2026-38428


JSON object : View

Products Affected

kestra

  • kestra
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')