Urgent.News

What's breaking now, across thousands of outlets.

Tech

The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation

The Suffix That Skipped Authentication: Kestra CVE-2026-49869 and Why Path Matching Is Not Authorisation An authentication filter that decides based on how a URL ends is not checking who you are. It is checking how a string looks. Kestra OSS shipped exactly that pattern, and in September 2026 CISA added the resulting vulnerability to its Known Exploited Vulnerabilities catalog with a three-day…

Kestra, an open-source workflow orchestrator, recently released a critical vulnerability CVE-2026-49869. This flaw is related to how Kestra handles URL paths and authentication. The AuthenticationFilter component in Kestra checks if a request is targeting a specific configuration endpoint by evaluating if the URL path ends with '/configs'.

This implementation assumes that only one endpoint should bypass Basic Auth authentication. However, the design flaw allows any API path ending in '/configs' to bypass authentication, not just the intended endpoint. This means an attacker could construct a URL that ends in '/configs' to gain unauthorized access and execute workflows without proper credentials.

The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog in September 2026, with a three-day federal remediation deadline. The CVSS vector for this vulnerability is high impact across confidentiality, integrity, and availability due to its low complexity, network reachability, and no requirement for user interaction.

To mitigate the risk, Kestra users are advised to upgrade to versions 1.0.45 or 1.3.21. As an interim measure, restricting API access at the network layer, enforcing authentication at an upstream proxy, and implementing additional checks for anomalous workflows or unexpected activities can help reduce the attack surface.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Istio 1.31 Adds Agentgateway Waypoints and Moves Release Artifacts off Google Cloud

Istio 1.31 adds agentgateway waypoints in ambient mode, with a canary configuration fix included in 1.31.1. It also ends the publication of images and Helm charts to Google Cloud, requiring repository…

  • Istio 1.31 introduces agentgateway as a Layer 7 waypoint proxy
  • Release moves container images and Helm charts off Google Cloud
  • Istio 1.31 adds traffic shifting between waypoints for canary deployments

Gas Optimization Audit: KuCoin

Gas Optimization Audit: KuCoin Target Protocol : KuCoin (TVL: $3564.8M) KuCoin – Gas‑Optimization Audit Report Protocol: KuCoin (DeFi & Exchange‑related smart‑contract suite) Scope: All…

  • KuCoin DeFi platform on Ethereum and L2 roll-ups
  • Gas optimization audit reveals 15%-45% higher transaction costs
  • Audit identifies 30% potential gas consumption reduction

Tododo: A Private To-Do App I Built for My Friend with Gemma + Ollama

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built Tododo is a to-do app for one very particular list: my friend Yathurshan's.

  • Tododo is a private to-do app built for friend Yathurshan
  • App processes plain sentences into tasks with subtasks and repeat rules
  • Uses Gemma AI model locally through Ollama, open-source code available

More from Saturday 3 October →