apache-airflow-core vulnerabilities
CVEs whose affected-version data names the apache-airflow-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.49%via OSV
CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.42%via OSV
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.45%via OSV
CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.43%via OSV
CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads
Apache Airflow allows code execution through crafted XCom payloads
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.82%via OSV