
Kestra patches critical SQL injection RCE in flows search
CVE-2026-34612 is a critical SQL injection in Kestra `< 1.3.7` that can escalate to OS command execution in default `docker-compose` deployments after login.
NewsAPI SecurityDevOps Security
2 minYesterday
