
Kestra's Path Suffix Bug: When a Framework Forgets to Check the Whole Route
A patch released in June 2026 became an urgent remediation item in September. The reason is not that the fix was wrong, but that CISA added the vulnerability to its Known Exploited Vulnerabilities catalog after evidence of real attacks. The case is a useful study in the gap between a patch existing and a risk being closed. What the vulnerability is

