apache-airflow has 45 CVEs on record between 2022 and 2026. Disclosures have slowed: 1 in the last 90 days after 24 in the 90 before. The busiest recent month was June 2026 with 16. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 24
Products
- apache-airflow 45
Worst active — by depth score
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…54CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine50CVE-2025-57735Critical· 9.1Apache Airflow: JWT token still valid after logout50CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability49CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output49
apache-airflow vulnerabilities
CVEs affecting apache-airflow, newest first. Open any entry for full detail, references, and exploit status.
45 CVEsRSS
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…
A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain…
CVE-2026-45426Low· 3.1Apache Airflow has an Incorrect Authorization issue
Apache Airflow has an Incorrect Authorization issue
CVE-2026-41014Medium· 4.3Apache Airflow has a Missing Authorization issue
Apache Airflow has a Missing Authorization issue
CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability
Apache Airflow has a Deserialization of Untrusted Data vulnerability
CVE-2026-46764Medium· 4.3Apache Airflow has an Authorization Bypass Through User-Controlled Key
Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2026-41084High· 7.5Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-40963Low· 3.1Apache Airflow has an Improper Authorization issue
Apache Airflow has an Improper Authorization issue
CVE-2026-42360Medium· 6.5Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-41017Medium· 5.9Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-40861Medium· 6.5Apache Airflow has a Link Following issue
Apache Airflow has a Link Following issue
CVE-2026-49267Medium· 5.9Apache Airflow has no certificate validation on SMTP STARTTLS connections
Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-42358Medium· 6.5Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-45360High· 7.3Apache Airflow Vulnerable to Deserialization of Untrusted Data
Apache Airflow Vulnerable to Deserialization of Untrusted Data
CVE-2026-48726Medium· 6.5Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
CVE-2026-40961High· 7.2Apache Airflow: Authenticated users can bypass the `is_safe_url` check
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-45192Medium· 6.5Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2026-40690Medium· 4.3Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
CVE-2026-38743Medium· 4.3Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInst…
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
CVE-2025-54550High· 8.1Apache Airflow: RCE by race condition in example_xcom dag
Apache Airflow: RCE by race condition in example_xcom dag
CVE-2026-31987High· 7.5Apache Airflow: JWT token appearing in logs
Apache Airflow: JWT token appearing in logs
CVE-2026-25219Medium· 6.5Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access
CVE-2026-34538Medium· 6.5Apache Airflow has an authorization bypass in DagRun wait endpoint
Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2025-57735Critical· 9.1Apache Airflow: JWT token still valid after logout
Apache Airflow: JWT token still valid after logout
CVE-2026-32794Medium· 4.8PoCApache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange
CVE-2024-56373High· 8.4Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
CVE-2025-27555Medium· 6.5Apache Airflow exposes sensitive information in its log files
Apache Airflow exposes sensitive information in its log files
CVE-2025-65995Medium· 6.5Apache Airflow error reporting may expose full kwargs
Apache Airflow error reporting may expose full kwargs
CVE-2026-22922Medium· 6.5Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
CVE-2026-24098Medium· 6.5Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users