PT-2026-70938 · Kestra · Kestra

CVE-2026-73247

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Kestra versions prior to 2.0.0
Description An issue exists where the http() function in HttpFunction.java passes a user-controlled URI argument to URI.create() and the server-side HTTP client. Because the system does not restrict private, loopback, or link-local destinations, an unauthenticated attacker can import and execute a flow to perform Server-Side Request Forgery (SSRF), enabling access to internal services or cloud metadata.
Recommendations Update to version 2.0.0 or later. As a temporary mitigation, restrict the use of the http() function within flows to prevent unauthorized internal requests.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73247

Affected Products

Kestra