Tag
high
advisory
Unauthenticated SSRF in Kestra OSS via Pebble http() Function
1 rule 3 TTPs 1 CVE 1 IOCAn unauthenticated SSRF vulnerability in the Kestra OSS Pebble template engine allows remote attackers to perform arbitrary requests to internal network services and cloud metadata endpoints.
Kestra OSS
ssrf
vulnerability
kestra
1r
3t
1c
1i
critical
advisory
Authentication Bypass and RCE in Kestra OSS
1 rule 3 TTPs 1 CVE 1 IOCKestra OSS versions 1.3.20 and below are vulnerable to an authentication bypass via an incorrectly implemented filter, enabling unauthenticated remote code execution with root privileges.
Kestra OSS
cve-2026-53576
rce
authentication-bypass
kestra
1r
3t
1c
1i
high
advisory
Kestra Orchestration Platform XSS Vulnerability (CVE-2026-33664)
2 rules 1 TTPKestra versions up to 1.3.3 are vulnerable to a cross-site scripting (XSS) vulnerability (CVE-2026-33664) allowing arbitrary JavaScript execution by viewing crafted flow metadata.
kestra
xss
cve-2026-33664
orchestration
2r
1t