apache-airflow has 45 CVEs on record between 2022 and 2026. Disclosures have slowed: 1 in the last 90 days after 24 in the 90 before. The busiest recent month was June 2026 with 16. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 24
Products
- apache-airflow 45
Worst active — by depth score
CVE-2026-33264Critical· 9.8A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler /…54CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine50CVE-2025-57735Critical· 9.1Apache Airflow: JWT token still valid after logout50CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability49CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output49
apache-airflow vulnerabilities
CVEs affecting apache-airflow, newest first. Open any entry for full detail, references, and exploit status.
45 CVEsRSS
CVE-2025-68675High· 7.5Apache Airflow proxy credentials for various providers might leak in task logs
Apache Airflow proxy credentials for various providers might leak in task logs
CVE-2025-68438High· 7.5Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
CVE-2025-54941MediumApache Airflow has a command injection vulnerability in "example_dag_decorator"
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
CVE-2025-62503Medium· 4.6Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache Airflow's create action can upsert existing Pools/Connections/Variables
CVE-2025-62402Medium· 5.4Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
CVE-2024-50378Medium· 6.5Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
Apache Airflow vulnerable to Insertion of Sensitive Information Into Sent Data
CVE-2024-45498High· 8.8Apache Airflow vulnerable to Improper Encoding or Escaping of Output
Apache Airflow vulnerable to Improper Encoding or Escaping of Output
CVE-2024-45034High· 8.8Apache Airflow vulnerable to Execution with Unnecessary Privileges
Apache Airflow vulnerable to Execution with Unnecessary Privileges
CVE-2024-41937Medium· 6.1Apache Airflow Cross-site Scripting Vulnerability
Apache Airflow Cross-site Scripting Vulnerability
CVE-2024-39863Medium· 5.4Apache Airflow Potential Cross-site Scripting Vulnerability
Apache Airflow Potential Cross-site Scripting Vulnerability
CVE-2024-39877High· 8.8Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
Apache Airflow has DAG Author Code Execution possibility in airflow-scheduler
CVE-2024-25142LowApache Airflow does not return the "Cache-Control" header for dynamic content
Apache Airflow does not return the "Cache-Control" header for dynamic content
CVE-2024-31869Medium· 4.3Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
CVE-2024-29735Medium· 5.3Apache Airflow Improper Preservation of Permissions vulnerability
Apache Airflow Improper Preservation of Permissions vulnerability
CVE-2022-40954Medium· 5.5OS Command Injection in Apache Airflow
OS Command Injection in Apache Airflow