{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kestra-oss--1.3.31--2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kestra:kestra:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-73247"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kestra OSS (\u003c= 1.3.31, \u003c 2.0.0)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","kestra"],"_cs_type":"advisory","_cs_vendors":["Kestra"],"content_html":"\u003cp\u003eKestra OSS versions up to 1.3.31 and versions prior to 2.0.0 contain a critical Server-Side Request Forgery (SSRF) vulnerability due to insufficient validation in the Pebble template engine's \u003ccode\u003ehttp()\u003c/code\u003e function. The vulnerability resides in \u003ccode\u003ecore/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java\u003c/code\u003e, where user-supplied URLs are processed by \u003ccode\u003eURI.create()\u003c/code\u003e without any sanitization or restriction on target destinations. An unauthenticated attacker can exploit this by uploading a malicious Flow YAML via the Kestra API. The lack of tenant authentication, combined with the ability to define arbitrary target schemes (including \u003ccode\u003efile://\u003c/code\u003e or \u003ccode\u003egopher://\u003c/code\u003e) and target ranges (including localhost or cloud metadata services like \u003ccode\u003e169.254.169.254\u003c/code\u003e), allows the attacker to exfiltrate cloud credentials, query internal infrastructure, or interact with restricted localhost services. This represents a significant risk for deployments running in cloud environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Kestra OSS instance reachable via the network.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious YAML flow configuration containing the \u003ccode\u003ehttp()\u003c/code\u003e function targeting an internal or metadata endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker uses a \u003ccode\u003ePOST\u003c/code\u003e request to \u003ccode\u003e/api/v1/main/flows/import\u003c/code\u003e to upload the malicious flow definition without requiring authentication.\u003c/li\u003e\n\u003cli\u003eAttacker uses a \u003ccode\u003ePOST\u003c/code\u003e request to the \u003ccode\u003e/api/v1/main/executions/\u003c/code\u003e endpoint to trigger the flow execution.\u003c/li\u003e\n\u003cli\u003eThe Kestra runner evaluates the Pebble template, invoking the \u003ccode\u003eHttpFunction.java\u003c/code\u003e logic with the attacker-controlled URI.\u003c/li\u003e\n\u003cli\u003eThe backend performs an outbound HTTP request from the server to the target internal/metadata service.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves the response data through the flow execution output or logs to exfiltrate sensitive metadata or service responses.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to bypass network boundaries. Attackers can exfiltrate sensitive information from cloud provider metadata endpoints (e.g., AWS/GCP/Azure instance metadata service), interact with internal services that are otherwise protected by firewalls, and potentially escalate privileges by harvesting cloud-assigned IAM roles or service credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate mitigation of CVE-2026-73247. Update Kestra OSS to a patched version (\u0026gt;= 1.3.32 or \u0026gt;= 2.0.0). Until updates are deployed, implement strictly scoped network egress controls for the Kestra server to prevent connections to internal RFC1918 subnets and the cloud provider metadata service (\u003ccode\u003e169.254.169.254\u003c/code\u003e). Monitor web server access logs for \u003ccode\u003ePOST\u003c/code\u003e requests to \u003ccode\u003e/api/v1/main/flows/import\u003c/code\u003e from untrusted or unexpected source IPs.\u003c/p\u003e\n","date_modified":"2026-09-17T19:11:18Z","date_published":"2026-09-17T19:11:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kestra-ssrf/","summary":"An unauthenticated SSRF vulnerability in the Kestra OSS Pebble template engine allows remote attackers to perform arbitrary requests to internal network services and cloud metadata endpoints.","title":"Unauthenticated SSRF in Kestra OSS via Pebble http() Function","url":"https://feed.craftedsignal.io/briefs/2026-09-kestra-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Kestra OSS (\u003c= 1.3.31, \u003c 2.0.0)","version":"https://jsonfeed.org/version/1.1"}