apache / airflow
34 known vulnerabilities in apache airflow.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-67260 | Medium | 0.8% | 7.3 | Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `… | |
| CVE-2026-45360 | Medium | 0.7% | 7.3 | Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomRef… | |
| CVE-2026-40961 | Medium | 0.6% | 7.2 | A bug in the login redirect route in Apache Airflow allowed authenticated users … | |
| CVE-2026-67587 | Medium | 0.6% | 8.8 | Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re… | |
| CVE-2026-42359 | Medium | 0.6% | 8.8 | A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` … | |
| CVE-2026-49298 | Medium | 0.5% | 8.8 | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker po… | |
| CVE-2026-58076 | Medium | 0.5% | 8.8 | Apache Airflow's serialization layer reconstructed exception nodes by calling `i… | |
| CVE-2026-41084 | Medium | 0.5% | 7.5 | A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{d… | |
| CVE-2026-68968 | Medium | 0.4% | 7.5 | Apache Airflow's Backfill API authorized a request against a Dag id supplied by … | |
| CVE-2026-42252 | Medium | 0.4% | 9.1 | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passin… | |
| CVE-2026-40861 | Low | 0.7% | 6.5 | A Dag author could either (a) create a symlink under their task's log directory … | |
| CVE-2026-48828 | Low | 0.7% | 6.5 | The Bulk Variables API in Apache Airflow called the redactor without passing the… | |
| CVE-2026-48892 | Low | 0.7% | 6.5 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (env… | |
| CVE-2026-49487 | Low | 0.7% | 6.5 | In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpo… | |
| CVE-2026-48891 | Low | 0.6% | 4.3 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied t… | |
| CVE-2026-59242 | Low | 0.6% | 5.4 | Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` end… | |
| CVE-2026-40963 | Low | 0.5% | 3.1 | The structure_data endpoint in the Airflow UI returned external dependency graph… | |
| CVE-2026-54183 | Low | 0.5% | 4.3 | Apache Airflow's secrets masker hides values stored under sensitive key names wh… | |
| CVE-2026-45192 | Low | 0.4% | 6.5 | A bug in the GET `/api/v2/connections/{connection_id}` REST API endpoint in Apac… | |
| CVE-2026-49296 | Low | 0.4% | 6.5 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose th… | |
| CVE-2026-65017 | Low | 0.4% | 6.5 | Apache Airflow's Config API did not mask team-scoped sensitive configuration val… | |
| CVE-2026-48726 | Low | 0.4% | 6.5 | A bug in Apache Airflow's auth manager logout handling left previously-issued JW… | |
| CVE-2026-41014 | Low | 0.4% | 4.3 | The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level a… | |
| CVE-2026-46764 | Low | 0.4% | 4.3 | The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache A… | |
| CVE-2026-45426 | Low | 0.4% | 3.1 | Exploitation requires the attacker to already be an authenticated Airflow worker… | |
| CVE-2026-68969 | Low | 0.4% | 6.5 | Apache Airflow wrote Variable values and Connection `extra` contents to the audi… | |
| CVE-2026-41017 | Low | 0.4% | 5.9 | Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Sec… | |
| CVE-2026-42358 | Low | 0.3% | 6.5 | A bug in Apache Airflow's Variable response masker caused nested-key redaction (… | |
| CVE-2026-42360 | Low | 0.3% | 6.5 | A bug in Apache Airflow's rendered-template field handling caused nested sensiti… | |
| CVE-2026-68076 | Low | 0.3% | 5.4 | Apache Airflow's environment-variable secrets backend resolved a team-scoped Con… | |
| CVE-2026-68971 | Low | 0.3% | 6.5 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}… | |
| CVE-2026-59244 | Low | 0.2% | 6.5 | Apache Airflow's secrets masker did not mask `var.json` Variable values whose va… | |
| CVE-2026-68970 | Low | 0.2% | 6.5 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON val… | |
| CVE-2026-49267 | Low | 0.2% | 5.9 | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers … |