← apache

apache / airflow

34 known vulnerabilities in apache airflow.

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-67260 Medium 0.8% 7.3 Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `…
CVE-2026-45360 Medium 0.7% 7.3 Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomRef…
CVE-2026-40961 Medium 0.6% 7.2 A bug in the login redirect route in Apache Airflow allowed authenticated users …
CVE-2026-67587 Medium 0.6% 8.8 Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re…
CVE-2026-42359 Medium 0.6% 8.8 A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` …
CVE-2026-49298 Medium 0.5% 8.8 A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker po…
CVE-2026-58076 Medium 0.5% 8.8 Apache Airflow's serialization layer reconstructed exception nodes by calling `i…
CVE-2026-41084 Medium 0.5% 7.5 A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{d…
CVE-2026-68968 Medium 0.4% 7.5 Apache Airflow's Backfill API authorized a request against a Dag id supplied by …
CVE-2026-42252 Medium 0.4% 9.1 Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passin…
CVE-2026-40861 Low 0.7% 6.5 A Dag author could either (a) create a symlink under their task's log directory …
CVE-2026-48828 Low 0.7% 6.5 The Bulk Variables API in Apache Airflow called the redactor without passing the…
CVE-2026-48892 Low 0.7% 6.5 The Config API in Apache Airflow surfaced per-key secrets-backend overrides (env…
CVE-2026-49487 Low 0.7% 6.5 In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpo…
CVE-2026-48891 Low 0.6% 4.3 A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied t…
CVE-2026-59242 Low 0.6% 5.4 Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` end…
CVE-2026-40963 Low 0.5% 3.1 The structure_data endpoint in the Airflow UI returned external dependency graph…
CVE-2026-54183 Low 0.5% 4.3 Apache Airflow's secrets masker hides values stored under sensitive key names wh…
CVE-2026-45192 Low 0.4% 6.5 A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apac…
CVE-2026-49296 Low 0.4% 6.5 Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose th…
CVE-2026-65017 Low 0.4% 6.5 Apache Airflow's Config API did not mask team-scoped sensitive configuration val…
CVE-2026-48726 Low 0.4% 6.5 A bug in Apache Airflow's auth manager logout handling left previously-issued JW…
CVE-2026-41014 Low 0.4% 4.3 The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level a…
CVE-2026-46764 Low 0.4% 4.3 The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache A…
CVE-2026-45426 Low 0.4% 3.1 Exploitation requires the attacker to already be an authenticated Airflow worker…
CVE-2026-68969 Low 0.4% 6.5 Apache Airflow wrote Variable values and Connection `extra` contents to the audi…
CVE-2026-41017 Low 0.4% 5.9 Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Sec…
CVE-2026-42358 Low 0.3% 6.5 A bug in Apache Airflow's Variable response masker caused nested-key redaction (…
CVE-2026-42360 Low 0.3% 6.5 A bug in Apache Airflow's rendered-template field handling caused nested sensiti…
CVE-2026-68076 Low 0.3% 5.4 Apache Airflow's environment-variable secrets backend resolved a team-scoped Con…
CVE-2026-68971 Low 0.3% 6.5 Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}…
CVE-2026-59244 Low 0.2% 6.5 Apache Airflow's secrets masker did not mask `var.json` Variable values whose va…
CVE-2026-68970 Low 0.2% 6.5 Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON val…
CVE-2026-49267 Low 0.2% 5.9 Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers …