VulnSea

apache-airflow vulnerabilities

CVEs whose affected-version data names the apache-airflow package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

53 CVEsRSS

CVE-2026-32794Medium· 4.8PoC
5mo ago

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

Twilightapache-airflow · apache-airflowEPSS 0.36%via OSV
CVE-2024-56373High· 8.4
7mo ago

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table

Twilightapache-airflow · apache-airflowEPSS 1.0%via OSV
CVE-2025-27555Medium· 6.5
7mo ago

Apache Airflow exposes sensitive information in its log files

Apache Airflow exposes sensitive information in its log files

Sunlitapache-airflow · apache-airflowEPSS 0.36%via OSV
CVE-2025-65995Medium· 6.5
7mo ago

Apache Airflow error reporting may expose full kwargs

Apache Airflow error reporting may expose full kwargs

Sunlitapache-airflow · apache-airflowEPSS 0.81%via OSV
CVE-2026-22922Medium· 6.5
7mo ago

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access

Sunlitapache-airflow · apache-airflowEPSS 0.39%via OSV
CVE-2026-24098Medium· 6.5
7mo ago

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users

Sunlitapache-airflow · apache-airflowEPSS 0.75%via OSV
CVE-2025-68675High· 7.5
8mo ago

Apache Airflow proxy credentials for various providers might leak in task logs

Apache Airflow proxy credentials for various providers might leak in task logs

Twilightapache-airflow · apache-airflowEPSS 2.0%via OSV
CVE-2025-68438High· 7.5
8mo ago

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated

Twilightapache-airflow · apache-airflowEPSS 0.66%via OSV
CVE-2025-54941Medium
10mo ago

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

Apache Airflow has a command injection vulnerability in "example_dag_decorator"

Sunlitapache-airflow · apache-airflowEPSS 0.46%via OSV
CVE-2025-62503Medium· 4.6
10mo ago

Apache Airflow's create action can upsert existing Pools/Connections/Variables

Apache Airflow's create action can upsert existing Pools/Connections/Variables

Sunlitapache-airflow · apache-airflowEPSS 0.40%via OSV
CVE-2025-62402Medium· 5.4
10mo ago

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

Apache Airflow `/api/v2/dagReports` executes DAG Python in API

Sunlitapache-airflow · apache-airflowEPSS 0.49%via OSV
CVE-2024-50378Medium· 6.5
1y ago

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data

Sunlitapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-45498High· 8.8
2y ago

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

Apache Airflow vulnerable to Improper Encoding or Escaping of Output

Twilightapache-airflow · apache-airflowEPSS 1.2%via OSV
CVE-2024-45034High· 8.8
2y ago

Apache Airflow vulnerable to Execution with Unnecessary Privileges

Apache Airflow vulnerable to Execution with Unnecessary Privileges

Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-41937Medium· 6.1
2y ago

Apache Airflow Cross-site Scripting Vulnerability

Apache Airflow Cross-site Scripting Vulnerability

Sunlitapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-39863Medium· 5.4
2y ago

Apache Airflow Potential Cross-site Scripting Vulnerability

Apache Airflow Potential Cross-site Scripting Vulnerability

Sunlitapache-airflow · apache-airflowEPSS 1.00%via OSV
CVE-2024-39877High· 8.8
2y ago

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler

Twilightapache-airflow · apache-airflowEPSS 1.7%via OSV
CVE-2024-25142Low
2y ago

Apache Airflow does not return the "Cache-Control" header for dynamic content

Apache Airflow does not return the "Cache-Control" header for dynamic content

Sunlitapache-airflow · apache-airflowEPSS 0.32%via OSV
CVE-2024-31869Medium· 4.3
2y ago

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used

Sunlitapache-airflow · apache-airflowEPSS 1.1%via OSV
CVE-2024-29735Medium· 5.3
2y ago

Apache Airflow Improper Preservation of Permissions vulnerability

Apache Airflow Improper Preservation of Permissions vulnerability

Sunlitapache-airflow · apache-airflowEPSS 1.5%via OSV
CVE-2023-46215High· 7.5
2y ago

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability

Twilightapache-airflow-providers-celery · apache-airflow-providers-celeryEPSS 1.2%via OSV
CVE-2023-39441Medium· 5.9
3y ago

Apache Airflow missing Certificate Validation

Apache Airflow missing Certificate Validation

Sunlitapache-airflow-providers-smtp · apache-airflow-providers-smtpEPSS 0.80%via OSV
CVE-2022-40954Medium· 5.5
3y ago

OS Command Injection in Apache Airflow

OS Command Injection in Apache Airflow

Sunlitapache-airflow · apache-airflowEPSS 1.4%via OSV
apache-airflow vulnerabilities (CVEs) — page 2 · VulnSea