{"slug": "kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route", "title": "Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route", "summary": "CISA added CVE-2026-49869, an unauthenticated OS command injection in the Kestra workflow orchestration platform, to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The flaw stems from an authentication filter that matched request paths by the suffix `/configs` rather than by exact route, allowing unauthenticated callers to create and execute workflows and achieve remote code execution. Kestra fixed the issue in versions 1.0.45 and 1.3.21, leaving 1.3.20 and earlier and 1.0.44 and earlier affected.", "body_md": "A patch released in June 2026 became an urgent remediation item in September. The reason is not that the fix was wrong, but that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The case is a useful study in the gap between a patch existing and a risk being closed.\n\nCVE-2026-49869 affects Kestra, an event-driven orchestration platform used for data, AI and infrastructure workflows. It is an operating system command injection reachable without authentication, rated 10.0 in the CISA KEV entry. The root cause is an authentication filter that matched request paths by suffix rather than by exact route.\n\nThe filter checked whether a path ended with `/configs`. A request to a path such as `/api/v1/main/flows/tutorial/configs` therefore passed the check. The filter did not verify that the request was actually addressed to the configuration endpoint, nor did it constrain the HTTP method. An unauthenticated caller could create a workflow and then trigger its execution.\n\nBecause Kestra workflows can run shell commands, the practical result is remote code execution with the privileges of the Kestra process.\n\nThe timeline is the instructive part:\n\nFour conditions have to be satisfied before a published patch actually removes risk from an environment:\n\nCISA adds a vulnerability to KEV when it has evidence of active exploitation. That is a different signal from a high CVSS score. A CVSS score describes potential severity in the abstract; a KEV listing describes observed attacker behavior against real targets.\n\nFor defenders, the KEV listing is a scheduling instruction. It says the theoretical risk has become a practical one, and the remediation window should be measured in days.\n\nKestra addressed the flaw in 1.0.45 and 1.3.21. Systems running 1.3.20 or earlier in the 1.3 line, or 1.0.44 or earlier in the 1.0 line, are affected.\n\nWhere immediate upgrade is not possible, the reported interim measure is to block, at a reverse proxy, requests that do not target `/api/v1/configs` but still end in `/configs`. Direct public access to the Kestra service port should be removed in any case. This is a compensating control, not a fix.\n\nFor environments that ran an affected version while reachable, the check should go beyond version confirmation:\n\n`/configs` from unfamiliar sources.\nCVE-2026-49869 is an authentication filter defect, which places it in a well-populated category. Filters that match on partial paths, that ignore the HTTP method, or that rely on string suffix comparisons rather than structured route matching tend to produce exactly this outcome: a route the developer did not intend to expose becomes reachable without credentials.\n\nThe defensive implication is that authentication checks should be expressed against the same route definitions the application uses to dispatch requests, not against string patterns that approximate them. When the two representations diverge, the gap is where bypasses live.\n\nThe public record establishes the flaw, the fixed versions and the KEV listing. It does not establish how many instances were attacked, what the attackers did after gaining execution, or whether the observed exploitation was targeted or opportunistic. Those questions remain open.", "url": "https://wpnews.pro/news/kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route", "canonical_source": "https://dev.to/jeffreyciend/kestras-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route-3ad8", "published_at": "2026-09-29 00:20:44+00:00", "updated_at": "2026-09-29 00:48:46.324910+00:00", "lang": "en", "topics": ["ai-infrastructure", "mlops", "ai-agents"], "entities": ["Kestra", "CISA", "CVE-2026-49869"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route", "markdown": "https://wpnews.pro/news/kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route.md", "text": "https://wpnews.pro/news/kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route.txt", "jsonld": "https://wpnews.pro/news/kestra-s-path-suffix-bug-when-a-framework-forgets-to-check-the-whole-route.jsonld"}}