CVE-2026-38428
EUVD-2026-2742605.05.2026, 19:16
Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a GET parameter is directly concatenated into an SQL query without proper sanitization or parameterization. As a result, attackers can inject arbitrary SQL expressions into the database query.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kestra | kestra | 𝑥 < 1.0.35 |
| kestra | kestra | 1.1.0 ≤ 𝑥 < 1.3.7 |
𝑥
= Vulnerable software versions