Daily digest
Saturday 18 April 2026
A quiet day: only 8 new CVEs against a recent average of about 48. Severity skewed high: 2 critical and 3 high, 63% of the total. 2 arrived with exploitation evidence or public exploit code already attached. apache-airflow-core was the most-affected vendor with 4.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2026-41242Critical· 9.8PoCprotobufjs compiles protobuf definitions into JavaScript (JS) functions
protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…
CVE-2026-41490High· 8.3PoCDagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
CVE-2026-41589Critical· 9.6Wish has SCP Path Traversal that allows arbitrary file read/write
Wish has SCP Path Traversal that allows arbitrary file read/write
CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads
Apache Airflow allows code execution through crafted XCom payloads
CVE-2026-40948Medium· 5.4apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
apache-airflow-providers-keycloak: Missing OAuth 2.0 State and PKCE Enables Login CSRF and Session Fixation
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Most-affected vendors
By CVEs published in the period.