apache-airflow
PyPI158 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting apache-airflowpage 4 of 4
- CVE-2026-68076MEDIUMCVSS 5.4EG 5.4fixed in 3.3.12026-08-12
vulnerable: 1.10.0 ... 3.3.1rc2 (297 versions)
Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to prevent this only ran when no team scope was supplied, and its pattern could not match a te…
- CVE-2026-68968HIGHCVSS 7.5EG 7.5fixed in 3.3.12026-08-12
vulnerable: 1.10.0 ... 3.3.1rc2 (297 versions)
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as py…
- CVE-2026-68969MEDIUMCVSS 6.5EG 6.5fixed in 3.3.12026-08-12
vulnerable: 1.10.0 ... 3.3.1rc2 (297 versions)
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recog…
- CVE-2026-68970MEDIUMCVSS 6.5EG 6.5fixed in 3.3.12026-08-12
vulnerable: 1.10.0 ... 3.3.1rc2 (297 versions)
Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserializ…
- CVE-2026-68971MEDIUMCVSS 6.5EG 6.5fixed in 3.3.12026-08-12
vulnerable: 1.10.0 ... 3.3.1rc2 (297 versions)
Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A …
- CVE-2026-75158MEDIUMCVSS 4.3EG 4.3fixed in 3.3.22026-09-21
vulnerable: 1.10.0 ... 3.3.2rc1 (299 versions)
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enu…
- CVE-2026-82355MEDIUMCVSS 4.2EG 4.22026-09-21
vulnerable: 1.10.0 ... 3.3.1 (296 versions)
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over …
- CVE-2026-86473CRITICALCVSS 9.1EG 9.1fixed in 3.3.22026-09-21
vulnerable: 3.0.0 ... 3.3.2rc1 (71 versions)
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout re…
Check whether apache-airflow is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for apache-airflow CVEs against the assets you own.
Book a Demo →