Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3529 articles · 209755 vulns · 37/41 feeds (7d)
← Back to list
8.6
CVE-2026-73247
kestra-io · kestra

Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

Description

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting private, loopback, or link-local destinations, allowing an unauthenticated attacker to import and execute a flow that accesses internal services or cloud metadata.

Affected Products

VendorProductVersions
kestra-iokestra< 2.0.0

References

  • https://github.com/kestra-io/kestra/security/advisories/GHSA-r56g-q4p6-m3p6(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB23d ago
CVE-2026-73247 | kestra-io Kestra up to 1.x Http Function HttpFunction.java http uri server-side request forgery
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-918
PublishedAug 11, 2026
Last enriched23d ago
Trending Score4
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-49869EXPKEV
Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`
Trending: 138
HIGHCVE-2026-73246
Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials
Trending: 4
HIGHCVE-2026-55839
Kestra: Stored XSS via custom Markdown [[link]] attribute injection
Trending: 4
MEDIUMCVE-2026-73245
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
Trending: 3
HIGHCVE-2026-49984
Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\..\` bypasses the `..` guard)

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026