CVE-2026-34612 | kestra-io kestra up to 1.3.6 Endpoint search sql injection (GHSA-365w-2m69-mp9x)
A vulnerability marked as critical has been reported in kestra-io kestra up to 1.3.6. This affects an unknown part of the file /api/v1/main/flows/search of the component Endpoint. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-34612. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.