Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…
CVE-2026-45426Low· 3.1Apache Airflow has an Incorrect Authorization issue
CVE-2026-41014Medium· 4.3Apache Airflow has a Missing Authorization issue
CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability
CVE-2026-46764Medium· 4.3Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2026-41084High· 7.5Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-40963Low· 3.1Apache Airflow has an Improper Authorization issue
CVE-2026-42360Medium· 6.5Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-41017Medium· 5.9Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-40861Medium· 6.5Apache Airflow has a Link Following issue
CVE-2026-49267Medium· 5.9Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-42358Medium· 6.5Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-45360High· 7.3Apache Airflow Vulnerable to Deserialization of Untrusted Data
CVE-2026-48726Medium· 6.5Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
CVE-2026-40961High· 7.2Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-45192Medium· 6.5Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2026-40690Medium· 4.3Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-38743Medium· 4.3Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2025-54550High· 8.1Apache Airflow: RCE by race condition in example_xcom dag
CVE-2026-31987High· 7.5Apache Airflow: JWT token appearing in logs
CVE-2026-25219Medium· 6.5Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2026-34538Medium· 6.5Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2025-57735Critical· 9.1Apache Airflow: JWT token still valid after logout
CVE-2026-32794Medium· 4.8PoCApache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.