What is CVE-2026-73247?
CVE-2026-73247 is a vulnerability in the Kestra orchestration platform affecting versions prior to 2.0.0. It allows Server-Side Request Forgery (SSRF) attacks because the 'http()' function does not restrict the user-controlled URI argument, potentially enabling access to private or loopback addresses. Users are advised to upgrade to version 2.0.0 or later.
Azərbaycanca: CVE-2026-73247 Kestra platformunda aşkarlanan boşluqdur. Bu zəiflik 2.0.0 versiyasından əvvəlki versiyalarda 'http()' funksiyasına ötürülən istifadəçi tərəfindən idarə olunan URI arqumentinin məhdudlaşdırılmaması səbəbindən Server-Side Request Forgery (SSRF) hücumlarına yol açır. İstifadəçilərə Kestra-nı ən azı 2.0.0 versiyasına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which platform and versions are affected by CVE-2026-73247?
This vulnerability affects versions of the Kestra platform prior to 2.0.0.
What is the root cause of the CVE-2026-73247 vulnerability?
The root cause is that the 'http()' function does not restrict the user-controlled URI argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.