apache-airflow-core has 5 CVEs on record. The busiest recent month was April 2026 with 4. The median CVSS is 7.2 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 0 prev 5
Products
- apache-airflow-core 5
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args48CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions41CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads40CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false29CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries20
apache-airflow-core vulnerabilities
CVEs affecting apache-airflow-core, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.49%via OSV
CVE-2026-32690Low· 3.7Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries
▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.42%via OSV
CVE-2026-30912Medium· 5.3Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false
▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.45%via OSV
CVE-2026-32228High· 7.5Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
Apache Airflow allows users with asset materialize permissions to trigger DAGs outside of their permissions
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.43%via OSV
CVE-2026-25917High· 7.2Apache Airflow allows code execution through crafted XCom payloads
Apache Airflow allows code execution through crafted XCom payloads
▾ Twilightapache-airflow-core · apache-airflow-coreEPSS 0.82%via OSV