CVE-2026-34612·Docker vulnerability
Kestra is an open-source, event-driven orchestration platform. Prior to version 1.3.7, Kestra (default docker-compose deployment) contains a SQL Injection vulnerability that leads to Remote Code Execution (RCE) in the following endpoint "GET /api/v1/main/flows/search". Once a user is authenticated, simply visiting a crafted link is enough to trigger the vulnerability. The injected payload is executed by PostgreSQL using COPY ... TO PROGRAM ..., which in turn runs arbitrary OS commands on the host. This issue has been patched in version 1.3.7.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.3.7
- Published
- 2026-04-03
Affected versions
Until: 1.3.7
Fixed in: 1.3.7
How to fix this CVE
Upgrade Docker to version 1.3.7 or later to patch the SQL injection vulnerability in the Kestra orchestration platform. This vulnerability allows authenticated users to execute arbitrary OS commands through a crafted URL to the /api/v1/main/flows/search endpoint. Immediate patching is critical due to the critical severity rating and the potential for complete system compromise.
sudo dnf update docker-ceDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET /api/v1/main/flows/search.*(%27|%22|%27%20OR|%27;|COPY|TO%20PROGRAM|union|select|exec|\x27)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or rate-limit requests to /api/v1/main/flows/search endpoint containing SQL metacharacters (single quotes, semicolons, SQL keywords like UNION, COPY, PROGRAM) in query parameters. Implement strict input validation and parameterized queries at the application layer. Require authentication and apply Web Application Firewall rules to detect and block SQL injection patterns in authenticated requests.How to check if you are affected
- Run 'docker --version' to check the installed Docker version and confirm it is 1.3.7 or later
- Check if Kestra is deployed via Docker Compose by looking for docker-compose.yml files and verify the Kestra service image tag using 'docker images | grep kestra'
- Review PostgreSQL query logs for suspicious COPY ... TO PROGRAM statements by checking '/var/lib/postgresql/data/log/' or container logs with 'docker logs {container_id} | grep COPY'
- Verify the patch by checking the Kestra service logs for version confirmation: 'docker exec {kestra_container} grep -i version /app/version.txt' or restart the container and confirm no SQL injection errors appear
FAQ
What is CVE-2026-34612?
CVE-2026-34612 is a critical SQL injection vulnerability in Kestra versions prior to 1.3.7 that allows authenticated users to execute arbitrary operating system commands on the host by visiting a specially crafted URL, exploiting PostgreSQL's COPY TO PROGRAM functionality.
Is CVE-2026-34612 being actively exploited?
No, CVE-2026-34612 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploit code has been released, but the critical severity and ease of exploitation warrant immediate patching.
What versions of Docker are affected by CVE-2026-34612?
All Kestra versions prior to 1.3.7 deployed in Docker environments are affected; the vulnerability resides in Kestra itself rather than Docker, but exploitation occurs within Docker-deployed instances.
How do I check if my server is vulnerable to CVE-2026-34612?
Run 'docker images | grep kestra' and verify the tag version; if it is below 1.3.7, your deployment is vulnerable. Additionally, check for the presence of the vulnerable endpoint by testing access to '/api/v1/main/flows/search'.
Does Defensia detect CVE-2026-34612?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker with Kestra is deployed on a monitored server, CVE-2026-34612 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-34612. Free for 1 server.
Get started free