apache-airflow vulnerabilities
CVEs whose affected-version data names the apache-airflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
53 CVEsRSS
CVE-2026-32794Medium· 4.8PoCApache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
CVE-2024-56373High· 8.4Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2025-27555Medium· 6.5Apache Airflow exposes sensitive information in its log files
Apache Airflow exposes sensitive information in its log files
CVE-2025-65995Medium· 6.5Apache Airflow error reporting may expose full kwargs
Apache Airflow error reporting may expose full kwargs
CVE-2026-22922Medium· 6.5Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
CVE-2026-24098Medium· 6.5Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
CVE-2025-68675High· 7.5Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2025-68438High· 7.5Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2025-54941MediumApache Airflow has a command injection vulnerability in "example_dag_decorator"
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
CVE-2025-62503Medium· 4.6Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2025-62402Medium· 5.4Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
CVE-2024-50378Medium· 6.5Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45034High· 8.8Apache Airflow vulnerable to Execution with Unnecessary Privileges
Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-41937Medium· 6.1Apache Airflow Cross-site Scripting Vulnerability
Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-39863Medium· 5.4Apache Airflow Potential Cross-site Scripting Vulnerability
Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39877High· 8.8Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-25142LowApache Airflow does not return the "Cache-Control" header for dynamic content
Apache Airflow does not return the "Cache-Control" header for dynamic content
CVE-2024-31869Medium· 4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
CVE-2024-29735Medium· 5.3Apache Airflow Improper Preservation of Permissions vulnerability
Apache Airflow Improper Preservation of Permissions vulnerability
CVE-2023-46215High· 7.5Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability
CVE-2023-39441Medium· 5.9Apache Airflow missing Certificate Validation
Apache Airflow missing Certificate Validation
CVE-2022-40954Medium· 5.5OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow