VulnSea

apache-airflow vulnerabilities

CVEs whose affected-version data names the apache-airflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

53 CVEsRSS

CVE-2026-82355Medium· 4.2
yesterday

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-75158Medium· 4.3
yesterday

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…

SunlitApache Software Foundation · apache-airflowvia NVD
CVE-2026-86473Critical· 9.1
yesterday

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …

MidnightApache Software Foundation · apache-airflowvia NVD
CVE-2026-75157NonePoC
4d ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

TwilightApache Software Foundation · apache-airflowEPSS 0.17%via NVD
CVE-2026-33264Critical· 9.8
2mo ago

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…

Midnightapache-airflow · apache-airflowEPSS 1.0%via OSV
CVE-2026-45426Low· 3.1
3mo ago

Apache Airflow has an Incorrect Authorization issue

Apache Airflow has an Incorrect Authorization issue

Sunlitapache-airflow · apache-airflowEPSS 0.36%via OSV
CVE-2026-41014Medium· 4.3
3mo ago

Apache Airflow has a Missing Authorization issue

Apache Airflow has a Missing Authorization issue

Sunlitapache-airflow · apache-airflowEPSS 0.37%via OSV
CVE-2026-42359High· 8.8
3mo ago

Apache Airflow has a Deserialization of Untrusted Data vulnerability

Apache Airflow has a Deserialization of Untrusted Data vulnerability

Twilightapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-46764Medium· 4.3
3mo ago

Apache Airflow has an Authorization Bypass Through User-Controlled Key

Apache Airflow has an Authorization Bypass Through User-Controlled Key

Sunlitapache-airflow · apache-airflowEPSS 0.37%via OSV
CVE-2026-41084High· 7.5
3mo ago

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

Twilightapache-airflow · apache-airflowEPSS 0.48%via OSV
CVE-2026-40963Low· 3.1
3mo ago

Apache Airflow has an Improper Authorization issue

Apache Airflow has an Improper Authorization issue

Sunlitapache-airflow · apache-airflowEPSS 0.48%via OSV
CVE-2026-42360Medium· 6.5
3mo ago

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Sunlitapache-airflow · apache-airflowEPSS 0.35%via OSV
CVE-2026-42252Critical· 9.1
3mo ago

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Midnightapache-airflow · apache-airflowEPSS 0.38%via OSV
CVE-2026-41017Medium· 5.9
3mo ago

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Sunlitapache-airflow · apache-airflowEPSS 0.35%via OSV
CVE-2026-40861Medium· 6.5
3mo ago

Apache Airflow has a Link Following issue

Apache Airflow has a Link Following issue

Sunlitapache-airflow · apache-airflowEPSS 0.69%via OSV
CVE-2026-49267Medium· 5.9
3mo ago

Apache Airflow has no certificate validation on SMTP STARTTLS connections

Apache Airflow has no certificate validation on SMTP STARTTLS connections

Sunlitapache-airflow · apache-airflowEPSS 0.18%via OSV
CVE-2026-42358Medium· 6.5
3mo ago

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Sunlitapache-airflow · apache-airflowEPSS 0.35%via OSV
CVE-2026-45360High· 7.3
3mo ago

Apache Airflow Vulnerable to Deserialization of Untrusted Data

Apache Airflow Vulnerable to Deserialization of Untrusted Data

Twilightapache-airflow · apache-airflowEPSS 0.68%via OSV
CVE-2026-48726Medium· 6.5
3mo ago

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

Sunlitapache-airflow · apache-airflowEPSS 0.38%via OSV
CVE-2026-40961High· 7.2
3mo ago

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

Apache Airflow: Authenticated users can bypass the `is_safe_url` check

Twilightapache-airflow · apache-airflowEPSS 0.65%via OSV
CVE-2026-45192Medium· 6.5
3mo ago

Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted users

Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted users

Sunlitapache-airflow · apache-airflowEPSS 0.43%via OSV
CVE-2026-40690Medium· 4.3
5mo ago

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions

Sunlitapache-airflow · apache-airflowEPSS 0.35%via OSV
CVE-2026-38743Medium· 4.3
5mo ago

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…

Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record

Sunlitapache-airflow · apache-airflowEPSS 0.35%via OSV
CVE-2026-32690Low· 3.7
5mo ago

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.42%via OSV
CVE-2025-54550High· 8.1
5mo ago

Apache Airflow: RCE by race condition in example_xcom dag

Apache Airflow: RCE by race condition in example_xcom dag

Twilightapache-airflow · apache-airflowEPSS 0.58%via OSV
CVE-2026-31987High· 7.5
5mo ago

Apache Airflow: JWT token appearing in logs

Apache Airflow: JWT token appearing in logs

Twilightapache-airflow · apache-airflowEPSS 0.74%via OSV
CVE-2026-25219Medium· 6.5
5mo ago

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Sunlitapache-airflow · apache-airflowEPSS 0.55%via OSV
CVE-2025-66236High· 7.5
5mo ago

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …

TwilightApache Software Foundation · apache-airflowEPSS 0.44%via CVEORG
CVE-2026-34538Medium· 6.5
5mo ago

Apache Airflow has an authorization bypass in DagRun wait endpoint

Apache Airflow has an authorization bypass in DagRun wait endpoint

Sunlitapache-airflow · apache-airflowEPSS 0.69%via OSV
CVE-2025-57735Critical· 9.1
5mo ago

Apache Airflow: JWT token still valid after logout

Apache Airflow: JWT token still valid after logout

Midnightapache-airflow · apache-airflowEPSS 0.67%via OSV
apache-airflow vulnerabilities (CVEs) · VulnSea