Apache Software Foundation Apache Airflow是Apache Software Foundation基金会的开源工作流调度与数据管道编排平台。 Apache Airflow 3.3.0之前版本存在信息泄露漏洞,该漏洞源于依赖调度图端点中对调用者可读Dag过滤器的应用不当,导致在触发/传感器依赖条目的dep.source和dep.target字段中泄露了未授权用户应ID标识符。未经授权的用户可利用此漏洞枚举其未授权读取的Dag标识符,从而引发信息泄露风险。以下版本受到影响
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow | < 3.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow | 0 ~ 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33264 | Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerial | |
| CVE-2026-49487 | Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs | |
| CVE-2026-48828 | Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called wit | |
| CVE-2026-49296 | Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagS | |
| CVE-2026-48892 | Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthet |
No comments yet