THREAT OPS › Threat News › [GHSA] GHSA-r56g-q4p6-m3p6 (high) — Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
[GHSA] GHSA-r56g-q4p6-m3p6 (high) — Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
GHSA-r56g-q4p6-m3p6 Severity: high CVE: CVE-2026-73247
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata
### Summary The Pebble template engine's `http()` function in Kestra OSS accepts user-controlled URLs without any validation, allowing Server-Side Request Forgery (SSRF) attacks. An unauthenticated attacker can import a malicious Flow
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-73247cve
- http://169.254.169.254/latest/meta-data/url
- 10.0.0.0/8cidr
- 192.168.0.0/16cidr
Original source: https://github.com/advisories/GHSA-r56g-q4p6-m3p6