Apache Airflow's API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the so
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Airflow | < 3.3.2 |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Airflow | 0 ~ 3.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94301 | 9.8 CRITICAL | Apache MINA: CVE-2026-47065 resolveProxyClass fix missing from 2.0.X and 2.1.X branches (2 |
| CVE-2026-47321 | 7.5 HIGH | Apache MINA: Unbounded Decompression Amplification DoS in Zlib.inflate |
| CVE-2026-91863 | Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows den | |
| CVE-2026-91864 | Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory | |
| CVE-2026-91865 | Apache Neethi: Crafted policy references cause exponential expansion during normalization | |
| CVE-2026-91866 | Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial | |
| CVE-2026-91867 | Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang t | |
| CVE-2026-82355 | Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, en | |
| CVE-2026-86473 | Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocabl |
No comments yet