The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation
DEV Community
The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation
Why a suffix-based authentication filter in Kestra OSS turned a path-matching shortcut into unauthenticated workflow execution, and what the fix reveals about route identity.
0 comments
No comments yet.