THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r56g-q4p6-m3p6 (high) — Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

[GHSA] GHSA-r56g-q4p6-m3p6 (high) — Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

highgithub_advisoriesPublished 2026-09-17

GHSA-r56g-q4p6-m3p6 Severity: high CVE: CVE-2026-73247

Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

### Summary The Pebble template engine's `http()` function in Kestra OSS accepts user-controlled URLs without any validation, allowing Server-Side Request Forgery (SSRF) attacks. An unauthenticated attacker can import a malicious Flow

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r56g-q4p6-m3p6