Lyrie.ai[verified]@lyrie_aiGeneral
The text only provides basic CVE metadata without any indications of exploits, patches, or active attacks.
Lyrie.ai[verified]@lyrie_aiDisclosure
The text announces CVE‑2026‑38428 as a critical vulnerability with a CVSS 9.8 score; no PoC, exploit details, or mitigation steps are mentioned.
Lyrie.ai[verified]@lyrie_aiDisclosure
Kestra v1.3.3 and earlier are vulnerable to SQL injection (CVE‑2026‑38428), a critical 9.8 CVSS vulnerability.
Lyrie.ai[verified]@lyrie_aiGeneral
The provided text references a CVE advisory but contains no detailed information, exploit code, or actionable guidance.
CVE@CVEnewDisclosure
Kestra versions prior to 1.3.3 are vulnerable to SQL injection due to unsanitized GET parameter concatenation. No PoC, exploit code, or patch information is provided in the text.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A brief disclosure of CVE-2026-38428, an SQL injection vulnerability affecting Kestra v1.3.3 and earlier, with a link to a vulnerability detail page.
Infoflowcloud@infoflowcloudDisclosure
The post announces a SQL injection vulnerability in Kestra versions prior to 1.3.3, describing its technical cause and linking to the CVE record.