PT-2026-70938 · Kestra · Kestra
CVE-2026-73247
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kestra versions prior to 2.0.0
Description
An issue exists where the
http() function in HttpFunction.java passes a user-controlled URI argument to URI.create() and the server-side HTTP client. Because the system does not restrict private, loopback, or link-local destinations, an unauthenticated attacker can import and execute a flow to perform Server-Side Request Forgery (SSRF), enabling access to internal services or cloud metadata.Recommendations
Update to version 2.0.0 or later.
As a temporary mitigation, restrict the use of the
http() function within flows to prevent unauthorized internal requests.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kestra