Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在反序列化注入漏洞,该漏洞源于BaseSerialization.deserialize()在Scheduler/API Server加载序列化DAG时,允许无限制地import_string()攻击者控制的类路径,导致DAG作者可嵌入恶意触发实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow | < 3.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow | 0 ~ 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49487 | Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs | |
| CVE-2026-48828 | Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called wit | |
| CVE-2026-49296 | Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagS | |
| CVE-2026-48891 | Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via tri | |
| CVE-2026-48892 | Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthet |
No comments yet