Detects Kestra instances before version 1.3.7 where the flow/execution search API's label filter parameter is concatenated directly into SQL queries without parameterization. A double-quote in the label key breaks the JSON string literal inside the SQL statement, allowing arbitrary SQL injection. On PostgreSQL deployments (the default), this enables remote code execution via COPY TO PROGRAM. The fix in 1.3.7 replaces string concatenation with jOOQ parameterized bind variables. Also tracked as CVE-2026-38428 by NVD — same advisory (GHSA-365w-2m69-mp9x), same patch.
Is your app exploitable through CVE-2026-34612?
Scan your domain free