Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Airflow — Vulnerabilities & Security Advisories 150

All 150 CVE vulnerabilities found in Apache Airflow, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Apache Airflow, an open-source workflow scheduler for data pipelines. It collects advisories related to common weakness classes such as remote code execution, SQL injection, and improper access control, covering the product’s vulnerability history from its early releases through recent updates. Readers can use this resource to track Apache Airflow’s advisory timeline, understand the prevalence of specific weakness types within the project, and review the cumulative exposure of the platform over time. The aggregation serves as a neutral reference for security teams evaluating patching priorities, auditors documenting risk, and developers investigating how historical flaws in the scheduling engine or web server components have evolved. No marketing language or introductory greetings are used; the content is strictly factual.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-86473 Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revocable only by expiry CWE-613 - - 2026-09-21
CVE-2026-75158 Apache Airflow: Assets events API returns asset events for every Dag with no per-Dag authorization filter CWE-200 - - 2026-09-21
CVE-2026-82355 Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation CWE-384 - - 2026-09-21
CVE-2026-75157 Apache Airflow: Asset queued-events DELETE endpoints gated on Dag READ instead of Dag EDIT (asset-triggered scheduling suppression) CWE-863 - - 2026-09-18
CVE-2026-59244 Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI CWE-312 - - 2026-08-12
CVE-2026-58076 Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server CWE-502 - - 2026-08-12
CVE-2026-59242 Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint CWE-502 - - 2026-08-12
CVE-2026-54183 Apache Airflow: Airflow Variables were not masked in the UI for authenticated users CWE-200 - - 2026-08-12
CVE-2026-67260 Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization CWE-502 - - 2026-08-12
CVE-2026-67587 Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget CWE-502 - - 2026-08-12
CVE-2026-65017 Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass) CWE-200 - - 2026-08-12
CVE-2026-68968 Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id CWE-436 - - 2026-08-12
CVE-2026-68969 Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext CWE-532 - - 2026-08-12
CVE-2026-68970 Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI CWE-312 - - 2026-08-12
CVE-2026-68971 Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints CWE-862 - - 2026-08-12
CVE-2026-68076 Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection CWE-639 - - 2026-08-12
CVE-2026-33264 Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize() CWE-502 - - 2026-07-07
CVE-2026-49487 Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs CWE-200 - - 2026-07-07
CVE-2026-48828 Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key CWE-200 - - 2026-07-07
CVE-2026-49296 Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id} CWE-639 - - 2026-07-07
CVE-2026-48891 Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target CWE-200 - - 2026-07-07
CVE-2026-48892 Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options CWE-200 - - 2026-07-07
CVE-2026-40861 Apache Airflow: Arbitrary File Read via Log Symlink following in FileTaskHandler CWE-59 - - 2026-06-01
CVE-2026-40961 Apache Airflow: Open Redirect Bypass Vulnerability CWE-601 - - 2026-06-01
CVE-2026-40963 Apache Airflow: DAG authorization bypass on /ui/structure/structure_data CWE-285 - - 2026-06-01
CVE-2026-41014 Apache Airflow: per-DAG RBAC bypass on /ui/partitioned_dag_runs endpoints CWE-862 - - 2026-06-01
CVE-2026-49267 Apache Airflow: No certificate validation on SMTP STARTTLS connections CWE-295 - - 2026-06-01
CVE-2026-41017 Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy CWE-614 - - 2026-06-01
CVE-2026-41084 Apache Airflow: API authorization bypass: bulk TaskInstances allows cross-DAG mutation CWE-639 - - 2026-06-01
CVE-2026-42252 Apache Airflow: BashOperator Jinja2 injection via dag_run.conf — low-privilege user pattern CWE-1336 - - 2026-06-01

All 150 known CVE vulnerabilities affecting Apache Airflow with full Chinese analysis, references, and POCs where available.